← Back to Feed
Hackers poison arrayref Rust crate to push infostealer malware
August 20, 2026 · BleepingComputer · Severity: HIGH
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. The malicious releases were published to crates.io and executed info-stealing payloads during the build process. The Rust Project quickly removed the malicious versions after detection. This attack highlights the risks of supply chain compromise in the Rust ecosystem.
Key Takeaways
- The maintainer account of the Rust crate arrayref was compromised to push malware during compilation.
- The malicious code executed during build processes, installing info-stealing malware.
- The Rust Project removed the malicious versions quickly after detection.