arrayref 공급망 공격이 확인되었으며, 여러 crate가 악성 의존성에 취약해졌다.
2026년 8월 20일, arrayref를 포함한 여러 crate가 악성 proc-macro1에 의존하도록 변조되는 공급망 공격이 발생했다. 이로 인해 proc-macro1의 빌드 스크립트가 악성 페이로드를 다운로드하는 등 보안 위협이 커졌다. 해당 공격은 개발자와 기업들에게 심각한 경각심을 불러일으킬 만한 사건이다.
A supply chain attack targeting arrayref and other crates has been identified.
On August 20, 2026, a supply chain attack was detected affecting arrayref and multiple crates by modifying dependencies to malicious proc-macro1. The build script of proc-macro1 downloaded a malicious payload, highlighting significant security vulnerabilities. This incident raises critical awareness among developers and companies regarding supply chain integrity.