Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245M Downloads
Executive Summary
The Rust Project removed malicious versions of three popular crates—arrayref 0.3.10, internment 0.8.7, and append‑only‑vec 0.1.9—after a compromised maintainer account published releases that added a typosquatted dependency. The dependency’s build script downloaded and executed a remote payload during compilation, affecting 245 million downloads. The crates were deleted from crates.io to stop further spread.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-20T20:22:35+00:00 - Category: threat-intel
Original Description: The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
"The industrial landscape is already littered with remains of once successful companies that could not adapt their strategic vision to altered conditions of competition."
— Abernathy