Supply chain attack on arrayref (Rust blog)
The Rust blog reportson a malicious crate, called proc-macro1, that was uploaded to thecrates.io repository.
Furthermore, we discovered that the popular arrayref cratehad recently been republished and made to depend on this crate,with the most recent versions yanked. We have removed the maliciousversion and unyanked the maliciously-yanked versions. Other cratesby that author (internment, append-only-vec) werealso affected so we have done the same for those, and locked theaccount as a precaution. We do not believe the author ofarrayref to be acting maliciously, but their computer orcredentials are likely compromised, and we are attempting tocontact them.