Back to advisories

Popular Rust Crates Compromised in Build-Time Supply Chain Attack

Three legitimate Rust crates (arrayref, internment, append-only-vec) were compromised with a malicious dependency that executes during build time. Any developer or CI/CD pipeline that built these packages between compromise and removal has potentially compromised systems with cross-platform malware capable of persistence and data exfiltration. This impacts the entire supply chain downstream of affected builds.

CRITICALAdvisoryAug 22, 2026
Action required
Immediately identify all internal builds that consumed arrayref, internment, or append-only-vec in the affected timeframe. Isolate those developer workstations and CI/CD agents, scan for proc-macro1 artifacts and browser data exfiltration indicators, then reimage systems before returning to service.
Affected products
arrayrefinternmentappend-only-vecproc-macro1proc-macro2