Rust crates arrayref & append-only-vec compromised via malicious proc-macro1 dependency
Blog post from Semgrep
On August 20, 2026, the widely used Rust crates arrayref and append-only-vec were compromised through malicious updates that added a dependency on proc-macro1, a typosquatted package impersonating the legitimate proc-macro2. Its build script executed automatically during Cargo builds, decoded obfuscated download URLs, retrieved platform-specific payloads for Linux, Windows, and macOS, and launched them as detached processes without requiring affected library functions to be called. A related package, proc-macro-en, appeared to impersonate arrayref maintainer droundy under the similar author name daveroundy, indicating broader campaign preparation. Organizations using proc-macro1 1.0.107, proc-macro-en 1.0.10, append-only-vec 0.1.9, or arrayref 0.3.10 were advised to rescan projects, review dependency and advisory records, and investigate identified command-and-control infrastructure and host artifacts.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.