Popular Rust crates arrayref, append-only-vec, and internment compromised in Supply Chain Attack
On August 20, we detected two popular Rust crates from the same maintainer, append-only-vec (4M downloads) and arrayref (244M downloads), were compromised. The attacker added a malicious dependency on a package called proc-macro1, which downloads a remote payload during the build and executes it on the developer's machine.