TL;DR
what: A compromised crates.io maintainer account published arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, each adding a single dependency on proc-macro1, a typosquat whose build script downloaded and executed a remote payload at compile time.
impact: arrayref has 245,385,500 all time downloads and 403 dependent crates, and the stage 2 implant persists on Windows, macOS, and Linux while stealing browser credentials from Chrome, Brave, and Edge.
fix: There is no CVE and no patched release: pin arrayref at 0.3.9 or earlier, which the Rust Security Response Team unyanked during the response, purge ~/.cargo/registry/cache, and block proc-macro1, proc-macro-en, aovine, arone, aronenao, and tinymember.
who: Any developer workstation or CI runner that built, checked, or tested a Rust project resolving a caret range on arrayref 0.3.x between 07:15 and 09:26 UTC on August 20, 2026.








