Malicious proc-macro1 crate and typosquats infect Rust arrayref 0.3.10 via supply-chain attack
Why it matters — This attack demonstrates how a single compromised dependency can propagate malicious code across widely used Rust crates. Engineers must verify their dependency trees to prevent latent infections. The incident highlights the fragility of supply-chain security even in curated ecosystems like crates.io
↗