Supply chain attack on arrayref
Summary
Rust's Security Response Team announced a supply chain attack involving a malicious build script in the proc-macro1 crate that affected arrayref and related crates. The malicious crate versions were deleted or unyanked, and the author's account was locked as a precaution. Developers are advised to audit dependencies and search local cargo caches for compromised crates.