Tag
A compromised release of the popular Rust crate `arrayref` contained a malicious build-time payload that executed remote code during compilation, affecting numerous downstream projects.
A supply-chain attack compromised the Rust crate arrayref, adding a malicious dependency that executes code at build time, affecting numerous downstream projects.