rust 크레이트 arrayref가 원격 페이로드를 실행하는 사례 발생.
2026년 8월 20일, crate.io에 게시된 rust 크레이트 arrayref 0.3.10에서 의존성으로 추가된 proc-macro1이 문제를 일으켰다. 컴파일 과정에서 원격에서 페이로드가 실행되는 악성 코드가 포함된 사례로, 사용자는 이 크레이트에 주의해야 한다. 이 사건은 rust 생태계에 악영향을 미칠 수 있으며, 타이포 스쿼팅 문제가 재차 부각되었다.
The rust crate arrayref executed a remote payload during the build process.
On August 20, 2026, the rust crate arrayref 0.3.10 was found to include the dependency proc-macro1, which executed a remote payload during the compilation process. This malicious code is a significant concern for users of the crate, forcing them to be vigilant. This incident highlights the ongoing issue of typosquatting in the rust ecosystem.