[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:popular-rust-crates-compromised-in-build-time-supply-chain-attack-mt4mqip2":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"e8256ba8-ff82-47ef-8196-d18d8a9ff49d","Popular Rust Crates Compromised in Build-Time Supply Chain Attack","popular-rust-crates-compromised-in-build-time-supply-chain-attack-mt4mqip2","Three legitimate Rust crates (arrayref, internment, append-only-vec) were compromised with a malicious dependency that executes during build time. Any developer or CI\u002FCD pipeline that built these packages between compromise and removal has potentially compromised systems with cross-platform malware capable of persistence and data exfiltration. This impacts the entire supply chain downstream of affected builds.","critical","advisory",[],[13,14,15,16,17],"arrayref","internment","append-only-vec","proc-macro1","proc-macro2","Immediately identify all internal builds that consumed arrayref, internment, or append-only-vec in the affected timeframe. Isolate those developer workstations and CI\u002FCD agents, scan for proc-macro1 artifacts and browser data exfiltration indicators, then reimage systems before returning to service.",[20],"f20294da-5032-4331-a53b-d2206876df29",null,[23],"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fpopular-rust-crates-compromised?utm_medium=feed","active","2026-08-24T17:05:46.044+00:00","2026-08-22T17:05:51.685463+00:00","2026-08-22T17:05:55.387764+00:00",[29],{"id":20,"title":6,"url":23}]