TL;DR

what: A compromised crates.io maintainer account published arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, each adding a single dependency on proc-macro1, a typosquat whose build script downloaded and executed a remote payload at compile time.

impact: arrayref has 245,385,500 all time downloads and 403 dependent crates, and the stage 2 implant persists on Windows, macOS, and Linux while stealing browser credentials from Chrome, Brave, and Edge.

fix: There is no CVE and no patched release: pin arrayref at 0.3.9 or earlier, which the Rust Security Response Team unyanked during the response, purge ~/.cargo/registry/cache, and block proc-macro1, proc-macro-en, aovine, arone, aronenao, and tinymember.

who: Any developer workstation or CI runner that built, checked, or tested a Rust project resolving a caret range on arrayref 0.3.x between 07:15 and 09:26 UTC on August 20, 2026.