Rust Supply-Chain Attack: arrayref 0.3.10 and the proc-macro1 Typosquat Execute a Remote Payload at Build Time - StepSecurity
The Rust crate arrayref 0.3.10 is compromised: it pulls in the typosquatted proc-macro1 1.0.107, whose build script downloads and runs a remote binary at build time. Full technical analysis: timeline, dropper dissection, runtime detection, IOCs, and remediation.