RUSTSEC-2026-0260

Source
https://rustsec.org/advisories/RUSTSEC-2026-0260
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0260.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0260
Published
2026-08-20T12:00:00Z
Modified
2026-08-21T06:30:03.170807339Z
Summary
`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency
Details

A new version of the arrayref crate was published with a direct dependency on proc-macro1, which would execute a malicious build script.

This compromised version was published on 2026-08-20 and removed approximately 86 minutes later. It was downloaded 2,285 times, which constituted less than 10% of arrayref download traffic across all versions, as most users had older versions of arrayref in their lockfiles.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / arrayref

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.3.10-0

Ecosystem specific

{
    "affects": {
        "arch": [],
        "os": [],
        "functions": []
    },
    "affected_functions": null
}

Database specific

informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0260.json"
categories
[
    "malicious"
]
cvss
null