← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 20, 2026 · 16:15via Cyber Security News

Popular Rust Packages With 244M Downloads Compromised to Run Malware

Brief

A major supply chain attack targeting the Rust ecosystem, in which two widely used crates, arrayref and append-only-vec , were hijacked to silently deliver malware the moment developers compiled their projects.

Together, the two packages account for hundreds of millions of downloads, making this one of the largest Rust crate compromises ever recorded by download volume.

Researchers at Aikido Security first spotted a new, suspicious package called proc-macro1 quietly downloading and executing a remote file during its build process.

Popular Rust Packages Compromised

The name was a deliberate typosquat of proc-macro2 , one of the most heavily relied-upon crates in the Rust world, and it copied the legitimate crate’s description and documentation to appear trustworthy.

Read more on Cyber Security News