Arrayref v0.3.10 and v0.3.11 compromised on crates.io

2 points by stevefan1999 14 hours ago

https://crates.io/crates/arrayref has a supply chain attack that runs malicious build script through a transient build-time dependency during `cargo build` with https://crates.io/crates/proc-macro-en/1.0.10/ (now deleted)

Some more context: https://github.com/rustsec/advisory-db/issues/3161

At the moment I cannot download the payloads anymore for further analysis.