RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0260

arrayref 0.3.10 was removed from crates.io due to a malicious dependency

Reported
Issued
Package
arrayref (crates.io)
Type
Vulnerability
Categories
References
Patched
no patched versions
Unaffected
  • <=0.3.9

Description

A new version of the arrayref crate was published with a direct dependency on proc-macro1, which would execute a malicious build script.

This compromised version was published on 2026-08-20 and removed approximately 86 minutes later, with no evidence of actual usage.

Advisory available under CC0-1.0 license.