# Compromised Rust package triggered malware during builds, SafeDep says

_Published Thursday, August 20, 2026 at 11:18 AM EDT · Security · Breaking · Tier 1 — Major_

![Compromised Rust package triggered malware during builds, SafeDep says — Primary](https://safedep.io/images/arrayref-blog-blanner.png)

A compromised release of Rust crate arrayref added a typosquatted dependency whose build script downloaded and ran a remote binary during compilation, according to SafeDep. The affected arrayref 0.3.10 release depended on proc-macro1 1.0.107, a renamed copy of proc-macro2 that retained normal library behavior while executing the payload. SafeDep says crates.io removed the malicious versions. The report says projects compiling dependency graphs that resolved to the bad version could trigger the script on supported platforms.

## Sources

- [safedep.io](https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/)

---
Canonical: https://techandbusiness.org/newswire/J5YyH1GyIgai4qRKDIiObk
Published: 2026-08-20T15:18:21.527Z
Story chronology: 2026-08-20T00:00:00.000Z
Retrieved: 2026-10-04T21:09:06.167Z
Publisher: Tech & Business (techandbusiness.org)
