arrayref
Macros to take array references of slices
Activity
- Latest release
- 3w ago
- Total releases
- 16
- Cadence
- ~2 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- BSD-2-Clause
- First release
- Aug 24, 2015
| Version | Released | |
|---|---|---|
0.3.10
patch
2 CVEs
RUSTSEC-2026-0260
Aug 20, 2026
`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency A new version of the This compromised version was published on 2026-08-20 and removed approximately
86 minutes later. It was downloaded 2,285 times, which constituted less than
10% of References Updated Aug 21, 2026 · Source: OSV.dev
MAL-2026-14336
Malware
Aug 20, 2026
Malicious code in arrayref (crates.io)
Critical
arrayref 0.3.10 was published to crates.io from a maintainer account (droundy) that appears to be compromised. Unlike every prior release, 0.3.10 declares a dependency on the malicious crate proc-macro1. The arrayref source itself is unchanged genuine macro code, but Cargo compiles the declared dependency, so building any project that resolves arrayref 0.3.10 pulls in and builds proc-macro1, whose build script downloads and executes an architecture-specific remote binary at build time from https://23.254.165.112:9089/ and passes 23.254.165.112:443 as a command-and-control address. Part of a coordinated crates.io campaign on 2026-08-20 that also trojanized internment and append-only-vec. The malicious release has been removed from crates.io; releases 0.3.9 and earlier are unaffected. Affected versions
0.3.10
References Updated Aug 21, 2026 · Source: OSV.dev | ||
0.3.9
unknown
| ||
0.3.8
unknown
| ||
0.3.7
unknown
| ||
0.3.6
unknown
| ||
0.3.5
unknown
| ||
0.3.4
unknown
| ||
0.3.3
unknown
| ||
0.3.2
unknown
| ||
0.3.1
unknown
| ||
0.3.0
unknown
| ||
0.2.2
unknown
| ||
0.2.1
unknown
| ||
0.2.0
unknown
| ||
0.1.1
unknown
| ||
0.1.0
unknown
|