The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
First seen on thehackernews.com
Jump to article: thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html
![]()

