← Terug naar overzicht

The arrayref crate version 0.3.10 for Rust has been identified as containing a rogue dependency that constitutes a supply chain attack. When developers compile a project that includes this crate, malicious code can be triggered during the build process. The rogue dependency registers with a command-and-control (C2) server, enabling arbitrary code execution on the victim's machine at compile time. This is a build-time malware attack, meaning developers do not need to run the software for compromise to occur. The attack was disclosed in August 2026 and has been documented across multiple security advisories including RustSec and the Rust language blog. The incident highlights risks associated with open-source dependency ecosystems and the potential for malicious packages to be introduced into trusted registries. Security researchers from SafeDep and StepSecurity have published analyses of the attack vector. The affected crate is listed in the RustSec advisory database under RUSTSEC-2026-0260.

Affected products

  • Rust
  • arrayref crate 0.3.10

Related CVE's

  • CVE-2026-77651

Categories

  • Ransomware & Malware
  • Supply Chain & Dependencies