# Compromised Rust package triggered malware during builds, SafeDep says

_Wednesday, August 19, 2026 at 8:00 PM EDT · Security · Breaking · Tier 1 — Major_

![Compromised Rust package triggered malware during builds, SafeDep says — Primary](https://safedep.io/images/arrayref-blog-blanner.png)

A compromised release of Rust crate arrayref added a typosquatted dependency whose build script downloaded and ran a remote binary during compilation, according to SafeDep. The affected arrayref 0.3.10 release depended on proc-macro1 1.0.107, a renamed copy of proc-macro2 that retained normal library behavior while executing the payload. SafeDep says crates.io removed the malicious versions. The report says projects compiling dependency graphs that resolved to the bad version could trigger the script on supported platforms.

## Sources

- [safedep.io](https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/)

---
Canonical: https://techandbusiness.org/newswire/J5YyH1GyIgai4qRKDIiObk
Retrieved: 2026-08-20T16:11:45.278Z
Publisher: Tech & Business (techandbusiness.org)
