Foresight News message: Rust has released an announcement stating that its popular crate arrayref was subjected to a supply-chain attack. The attacker is suspected to have compromised an account credential and published a malicious proc-macro1 version. The version was uploaded to crates.io and removed about 86 minutes later. Other related crates were also affected during the same period. The Rust security response team recommends that users check their local dependency caches.

Afterward, Solana’s core development team, Anza, confirmed via a tweet that it is aware of the incident. Agave and Anza software were not affected, and users who ran cargo update today are reminded to check against the official indicators.