Compromised Rust crates arrayref and append-only-vec execute remote payload at build time via malicious proc-macro1 dependency
Why it matters — Because the malicious code runs in build.rs, merely compiling a project that depends on either crate triggers the infection without calling any crate functionality. With arrayref at 244 million downloads and append-only-vec at 4 million, this is the largest Rust crate compromise by download count.
↗