Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-20 ยท updated: 2026-08-22 ยท tags: [incident, breach] ยท confidence: high ยท affected_sectors: [sector-technology] ยท au_impact: false

The Rust Project deleted malicious versions of three widely used crates โ€” arrayref, internment and append-only-vec โ€” from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The releases, published on 20 August, were removed within 86โ€“107 minutes; RustSec advisories record no evidence any malicious version was used. Developers are advised to search ~/.cargo/registry/cache for deleted crate files and pin arrayref at 0.3.9 or earlier.