# A Rust crate ran malware at compile time. 86 minutes.

Published: 2026-09-15

A four-macro Rust crate with 260 million downloads adds one dependency, and \`cargo build\` runs a stranger's binary on your machine. August 20, 2026: arrayref 0.3.10 lands on crates.io depending on proc-macro1 — not proc-macro2, the real one — whose build script downloads a payload, drops it in /tmp/rust-setup and spawns it detached while your project compiles. The clean versions are yanked so Cargo's own warning walks you to the poisoned one. 86 minutes later it is deleted.

Canonical: https://thedailydiff.dev/video/2026-09-15-arrayref-proc-macro/

## What this video covers

- cargo build runs a stranger's binary
- The receipts: Rust Blog, SafeDep, Hacker News
- This is The Daily Diff, postmortem
- Timeline: 02:11 staging → 07:15 published → 08:41 deleted
- Mechanism: build.rs, no sandbox, the yank lure

## Chapters

- 0:00 cargo build runs a stranger's binary
- 0:20 The receipts: Rust Blog, SafeDep, Hacker News
- 0:33 This is The Daily Diff, postmortem
- 0:40 Timeline: 02:11 staging → 07:15 published → 08:41 deleted
- 1:25 Mechanism: build.rs, no sandbox, the yank lure
- 2:05 git blame — the split
- 2:25 Blast radius: 2,285 downloads
- 2:45 Verdict + the Monday line

## Transcript

### cargo build runs a stranger's binary

0:00 A four-macro Rust crate with a quarter of a billion downloads adds one dependency, and cargo build runs a stranger's binary on your machine. August 20th, 2026. arrayref 0.3.10 lands on crates.io depending on proc-macro1. Not proc-macro2, the real one: one digit off, and its build script runs a payload while your project compiles. Rust's security team deletes it 86 minutes later.

### The receipts: Rust Blog, SafeDep, Hacker News

0:22 SafeDep publishes the teardown. Hacker News: 554 points. How it happens, why Cargo lets it, and who gets the blame. This is The Daily Diff, postmortem. Two a.m., UTC.

### This is The Daily Diff, postmortem

0:33 An account called d-tolney, one letter from David Tolnay, who maintains half of Rust, publishes proc-macro1 1.0.106: real

### Timeline: 02:11 staging → 07:15 published → 08:41 deleted

0:41 proc-macro2, renamed. Staging. 07:11. Version 1.0.107 adds a build script, plus base64, TLS and an HTTP client. For a token parser. 07:15. The maintainer's account republishes arrayref as 0.3.10 and yanks every older version. Cargo prints: consider updating to a version that is not yanked. The only one left is the poisoned one.

1:02 The warning is the lure. Same minute, a security firm reports it to Rust. 07:54, a RustSec issue. 08:29, an issue on the repo; the attacker answers with 0.3.11 and a second malicious dependency. 08:41, deleted. Eighty-six minutes. Why? One: Cargo builds every declared dependency, called or not. One manifest line is enough.

1:21 Two: a build script runs on your machine, as you, with your SSH keys and cargo

### Mechanism: build.rs, no sandbox, the yank lure

1:26 token, before your code compiles. No sandbox, by design: it's how crates find C libraries. Three: inside is real proc-macro2, so the build succeeds. The payload: a TLS client that trusts any certificate fetches a binary, drops it in /tmp/rust-setup and spawns it detached. On Windows it detours through wscript to escape Cargo's job object; a source comment says so. The second stage, per the RustSec thread: a remote-access tool aimed at

1:52 browsers and crypto wallets. Poetic, since arrayref's biggest users include secp256k1 and Solana. git blame. Cargo's model, fifty-five percent: dependencies run code on your machine at compile time, no sandbox, and the yank warning walked people to the

### git blame — the split

2:07 poison. One account, thirty: one credential republishes a crate a quarter of a billion downloads trust. The digit one, fifteen: one keystroke from Rust's most trusted crate, and nobody reads the tree. Blast radius: 2,285 downloads in 86 minutes. Under ten percent of traffic, because most lockfiles held 0.3.9. crates.io says no evidence of usage.

### Blast radius: 2,285 downloads

2:27 Two people on the RustSec thread disagree; one finds a systemd service. On Hacker News the top thread isn't about the malware. It's the crate page, where 0.3.10 now never existed. Verdict, postmortem: needs review. Eighty-six minutes to delete, a same-day blog post, the account locked: that part is ship it. But the crate page shows nothing happened, cargo audit stays silent on a cached

### Verdict + the Monday line

2:48 copy, and build scripts still run as you. Monday: run the Rust blog's find command, and treat a yank warning as a question, not an instruction. Send me the incident you're still not allowed to talk about, in the comments, or at the daily diff dot dev. And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.

## Sources

- [Rust Blog, "Supply chain attack on arrayref" (security-response, Aug 20, 2026)](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/) — blog.rust-lang.org
- [RUSTSEC-2026-0260 (arrayref)](https://github.com/rustsec/advisory-db/blob/main/crates/arrayref/RUSTSEC-2026-0260.md) — github.com
- [RustSec issue #3161 (the original report, IOCs, victims)](https://github.com/rustsec/advisory-db/issues/3161) — github.com
- [SafeDep technical analysis](https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/) — safedep.io
- [GitHub issue on the repo (0.3.11 spotted)](https://github.com/droundy/arrayref/issues/33) — github.com
- [crates.io](https://crates.io/crates/arrayref) — crates.io
- [Hacker News (554 points)](https://news.ycombinator.com/item?id=49374269) — news.ycombinator.com
- [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/) — www.bleepingcomputer.com
