VDB
KO

RUSTSEC-2026-0260

`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency

Details

A new version of the `arrayref` crate was published with a direct dependency on `proc-macro1`, which would execute a malicious build script.

This compromised version was published on 2026-08-20 and removed approximately 86 minutes later, with no evidence of actual usage.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io / arrayref
Introduced in: 0.3.10-0

No fixed version published yet for arrayref. Pin to a known-safe version or switch to an alternative.

References