Security3 min read
Malicious crate hit Rust’s arrayref package for 86 minutes
The Rust Security Response Team said a malicious proc-macro1 crate used a build script to download a payload, and that the popular arrayref crate was republished to depend on it. arrayref 0.3.10 was online for 86 minutes, from 07:15 to 08:41 UTC.
