Home / Companies / Semgrep / Blog / Post Details
Content Deep Dive

Rust crates arrayref & append-only-vec compromised via malicious proc-macro1 dependency

Blog post from Semgrep

Post Details
Company
Date Published
Author
Diptendu Kar
Word Count
260
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

On August 20, 2026, the widely used Rust crates arrayref and append-only-vec were compromised through malicious updates that added a dependency on proc-macro1, a typosquatted package impersonating the legitimate proc-macro2. Its build script executed automatically during Cargo builds, decoded obfuscated download URLs, retrieved platform-specific payloads for Linux, Windows, and macOS, and launched them as detached processes without requiring affected library functions to be called. A related package, proc-macro-en, appeared to impersonate arrayref maintainer droundy under the similar author name daveroundy, indicating broader campaign preparation. Organizations using proc-macro1 1.0.107, proc-macro-en 1.0.10, append-only-vec 0.1.9, or arrayref 0.3.10 were advised to rescan projects, review dependency and advisory records, and investigate identified command-and-control infrastructure and host artifacts.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.