Heads up for anyone writing Rust today.
The Rust Security Response Team just disclosed a supply chain attack. The popular arrayref crate was republished to pull in a malicious dependency that downloaded a payload through its build script.
arrayref isn't obscure. If you or your dependencies pulled it recently, you'll want to check now.
The malicious versions to look for:
> arrayref 0.3.10
> internment 0.8.7
> append-only-vec 0.1.9
> proc-macro1, plus typosquats: proc-macro-en, aovine, arone, aronenao, tinymember
All deleted from and the maintainer's account is locked. The team believes the author's credentials were compromised rather than the author acting maliciously.
Full advisory, including the one-line command to scan your local cargo cache: