Yesterday's arrayref compromise was a build script that ran malware at compile time, and a crate with 244M downloads carried it. Anyone who compiled a project that pulled it in got hit, without ever calling the crate.
So here's how you actually lower your odds of catching one of these.
> Commit your Cargo.lock, and build from it.
The lock file pins exact versions. If your CI resolves fresh dependencies on every build, you inherit whatever got published overnight. Build from the lock, not from the latest.
> Don't auto-resolve new versions in CI.
Use --locked in your build and test steps so cargo fails instead of silently pulling something new. A failed build is a signal. A silent upgrade is a liability.
> Update dependencies on a schedule, not continuously.
Bump deps deliberately, once a quarter or so, and review what changed. Most of these attacks get caught and patched within hours, so lagging slightly behind the bleeding edge is a feature, not a bug.
> Treat build scripts as untrusted code.
runs with your permissions at compile time. That's the whole attack surface here. Tools like cargo-vet and cargo-deny help you audit what's actually running.
None of this makes you bulletproof. It makes you a harder, slower target, which for supply chain attacks is most of the battle.
@m4rio_eth put together a diagnostic prompt for exactly this incident. Check his post and run it over your own system, it scans your repo and machine for the compromise indicators and reports back without touching anything.
Stay paranoid about what you compile. Stay safe. Stay Rektoff.
Heads up for anyone writing Rust today.
The Rust Security Response Team just disclosed a supply chain attack. The popular arrayref crate was republished to pull in a malicious dependency that downloaded a payload through its build script.
arrayref isn't obscure. If you or your dependencies pulled it recently, you'll want to check now.
The malicious versions to look for:
> arrayref 0.3.10
> internment 0.8.7
> append-only-vec 0.1.9
> proc-macro1, plus typosquats: proc-macro-en, aovine, arone, aronenao, tinymember
All deleted from and the maintainer's account is locked. The team believes the author's credentials were compromised rather than the author acting maliciously.
Full advisory, including the one-line command to scan your local cargo cache:
もっと見る