# Compromised Rust packages ran malware during compilation

_Thursday, August 20, 2026 at 3:15 AM EDT · Security · Breaking · Tier 1 — Major_

![Compromised Rust packages ran malware during compilation — Primary](https://www.bleepstatic.com/content/hl-images/2024/04/09/Rust-headpic-red.jpg)

Attackers compromised the maintainer account for the Rust crate arrayref and used it to publish a malicious release that executed malware during compilation, BleepingComputer reported. Two other crates, append-only-vec and internment, were also poisoned. The injected proc-macro1 dependency used a build script to select a payload for the host operating system. Crates.io removed the releases after the incident was reported. Developers who installed affected versions during the exposure window are advised to assume compromise.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/)

---
Canonical: https://techandbusiness.org/newswire/A47644uYgy4Xk7mkqNuENz
Retrieved: 2026-08-21T00:08:36.932Z
Publisher: Tech & Business (techandbusiness.org)
