Malicious updates turned routine builds into a delivery system for infostealer malware

Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation.

Rust deletes malicious releases of three crates after a proc-macro1 build script downloaded and ran a remote payload during compilation.