Rust Supply-Chain Attack: arrayref 0.3.10 and the proc-macro1 Typosquat Execute a Remote Payload at Build Time
Summary
Researchers report that the Rust crate arrayref 0.3.10 was compromised via a typosquatted proc-macro1, which downloaded and executed a payload during cargo build. The post traces the attack timeline, indicators of compromise, and remediation guidance for affected lockfiles and credentials, highlighting build-time execution risks in CI/CD pipelines.