{"id":"RUSTSEC-2026-0260","summary":"`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency","details":"A new version of the `arrayref` crate was published with a direct dependency\non `proc-macro1`, which would execute a malicious build script.\n\nThis compromised version was published on 2026-08-20 and removed approximately\n86 minutes later. It was downloaded 2,285 times, which constituted less than\n10% of `arrayref` download traffic across all versions, as most users had older\nversions of `arrayref` in their lockfiles.","modified":"2026-08-21T06:30:39.168632791Z","published":"2026-08-20T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/arrayref"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0260.html"},{"type":"WEB","url":"https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"}],"affected":[{"package":{"name":"arrayref","ecosystem":"crates.io","purl":"pkg:cargo/arrayref"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.3.10-0"}]}],"ecosystem_specific":{"affects":{"functions":[],"arch":[],"os":[]},"affected_functions":null},"database_specific":{"cvss":null,"informational":null,"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0260.json","categories":["malicious"]}}],"schema_version":"1.9.0"}