Arrayref versions 0.3.10 and 0.3.11 were reportedly compromised on crates.io; the incident report says 0.3.10 introduced a dependency on the typosquatted `proc-macro1` 1.0.107 crate. This is a Rust software-supply-chain incident involving a malicious dependency introduced through the build ecosystem. The supplied search snippets establish that crates.io and RustSec remove and document malicious crates generally, but they do not independently confirm Arrayref’s precise exposure, the maintainer’s response, or that remediation fully eliminated this dependency path.
2026-08-25T15:47:16Z
After repeated stale checks, no authoritative exposure assessment, scope expansion, maintainer response, or remediation result has emerged; secondary discussion has exhausted its signal value. Expire the episode and reopen only if an advisory, investigation finding, or operational remediation update appears.
2026-08-23T15:39:49Z
The latest refresh remains repetitive ecosystem discussion, not evidence resolving exposure, affected scope, maintainer response, or remediation. Stop repricing on comment churn and await an authoritative advisory or investigation update.
2026-08-22T14:37:17Z
Higher engagement and refreshed comments remain secondary discussion of build sandboxing and dependency hygiene, not new evidence about exposure, affected scope, maintainer response, or remediation. The case remains open but cold pending an authoritative operational update.
2026-08-21T14:36:06Z
The latest refresh is still ecosystem-level discussion rather than authoritative evidence about exposure, affected scope, maintainer response, or remediation. Comment churn no longer changes the case; await an operational update.
2026-08-21T13:31:35Z
The refreshed comments remain general build-sandboxing and dependency-hygiene discussion, adding no authoritative exposure assessment, maintainer response, scope change, or remediation result. Comment churn no longer changes the case; await an operational update.
2026-08-21T12:27:35Z
The refreshed comments remain architectural debate and add no authoritative evidence about exposure, affected scope, maintainer action, advisory status, or remediation. Repetitive discussion churn no longer changes the incident’s meaning; await an operational update.
2026-08-21T11:29:46Z
The latest comment refresh remains repetitive discussion of Cargo sandboxing and dependency hygiene, not evidence about exposure, affected scope, maintainer action, or remediation. Keep the incident open but cold pending an authoritative operational update.
2026-08-21T10:30:40Z
The refreshed comments remain ecosystem-level debate and provide no authoritative exposure assessment, scope change, maintainer response, advisory, or remediation result. Comment churn no longer changes the case; keep it cold pending an operational update.
2026-08-21T09:29:14Z
The latest refresh remains repetitive architectural discussion rather than evidence about exposure, affected scope, maintainer action, or remediation. Keep the incident open but cold and stop treating comment churn as a reason for frequent review.
2026-08-21T07:25:29Z
The refreshed comments remain architectural debate and secondary observations, not authoritative evidence about exposure, affected scope, maintainer action, or remediation. Repeated discussion churn does not change the incident’s meaning; keep it open but review less frequently pending an operational update.
2026-08-21T06:28:42Z
The refreshed comments remain general build-sandboxing and dependency-hygiene debate, not new evidence about exposure, affected scope, maintainer response, or remediation. The incident remains open but cold pending an authoritative operational update.
2026-08-21T05:23:45Z
The refreshed comments and negligible engagement movement add no authoritative exposure assessment, scope change, maintainer response, or remediation result. Discussion churn remains repetitive, so await an operational update rather than continuing frequent review.
2026-08-21T03:28:20Z
The refreshed comments remain architectural discussion rather than evidence about exposure, affected scope, maintainer action, or remediation. Repeated discussion churn no longer warrants hourly review; await an authoritative operational update.
2026-08-21T02:23:36Z
The latest comment refresh remains general discussion of Cargo sandboxing and dependency hygiene, with no authoritative change to exposure, affected scope, maintainer action, or remediation. This is repetitive amplification, so the case remains open but cold.
2026-08-21T01:24:23Z
Refreshed comments remain ecosystem-level debate and add no authoritative exposure assessment, maintainer response, scope change, or remediation evidence. The incident stays open but cold pending an operational update.
2026-08-21T00:25:13Z
The refreshed discussion remains repetitive debate about build isolation and dependency hygiene, without authoritative evidence on exposure, affected scope, maintainer action, or remediation. The incident stays open but cold pending an operational update.
2026-08-20T23:34:24Z
The refreshed comments remain general discussion of Cargo sandboxing and dependency hygiene, with no authoritative finding on exposure, affected scope, maintainer action, or remediation. This is repetitive amplification rather than a change in the incident’s meaning.
2026-08-20T22:34:54Z
The refreshed comments remain repetitive architectural discussion and add no authoritative exposure assessment, maintainer response, scope expansion, or remediation evidence. Keep the incident open but cold pending an operational update.
2026-08-20T21:30:59Z
The refreshed comments remain architectural debate about Cargo sandboxing and dependency hygiene, without new evidence on exposure, maintainer action, affected scope, or remediation. This is repetitive amplification, so the case stays open but cold pending an authoritative operational update.
2026-08-20T20:36:58Z
The refreshed discussion remains general debate about Cargo sandboxing and dependency hygiene, with no new evidence on exposure, maintainer action, affected scope, or remediation. Keep the incident open but cold pending an authoritative operational update.
2026-08-20T19:43:07Z
The refreshed comments remain ecosystem-level debate about Cargo sandboxing and dependency hygiene, adding no authoritative exposure assessment, maintainer response, or remediation result. The case stays open but cold pending operational evidence.
2026-08-20T18:33:48Z
Repeated comment refreshes remain general debate about Cargo sandboxing and dependency hygiene, not new evidence about exposure, maintainer action, or remediation. Keep the incident open but cold pending an authoritative operational update.
2026-08-20T15:40:53Z
Refreshed comments continue debating build-script sandboxing and dependency hygiene but add no authoritative exposure, maintainer, or remediation evidence. This is repetitive amplification, so the incident remains open and cool.
2026-08-20T14:39:48Z
Front-page discussion broadens attention to build isolation and registry controls but remains secondary amplification of the known compromise. No authoritative exposure finding, maintainer response, expanded affected scope, or completed remediation changes the case’s meaning.
2026-08-20T14:24:14Z
evidence attached: hn.story.49374269 — Front-page HN coverage independently corroborates the compromised Arrayref build-time payload and raises ecosystem visibility.
2026-08-20T11:31:31Z
The additional HN post only repeats the known compromise and does not establish exposure, maintainer action, or complete remediation. Keep the incident open but cool pending authoritative investigation or operational guidance.
2026-08-20T11:23:18Z
evidence attached: hn.story.49372841 — Independent HN coverage corroborates the compromised Rust crate episode and warrants tracking maintainer remediation and exposure.
2026-08-20T10:34:52Z
The added item reinforces that a malicious ArrayRef release occurred but supplies no independent exposure finding, maintainer response, or proof of complete remediation. It is repetitive amplification of the already-routed incident, so the case remains open without renewed heat.
2026-08-20T10:22:30Z
evidence attached: hn.story.49372310 — Direct first-party corroboration of the open ArrayRef compromise case, specifically the malicious 0.3.10 release.
2026-08-20T09:39:11Z
No new investigation, maintainer response, exposure finding, or remediation evidence has arrived; this is only an unchanged reobservation of the already-alerted incident. Cool the case while keeping it open for authoritative follow-up.
2026-08-20T09:31:16Z
grounded: known/low — This is a Rust-specific instance of dependency risk already covered by Scott’s Sovereign Software Assurance requirement that dependencies be explicit, auditable
2026-08-20T09:28:48Z
origin walked (codex/luna, conf 0.98): anchor hn.story.49372246 -> echo.github.25c8718429 by jhobern
2026-08-20T09:27:43Z
case created — The report identifies specific compromised package versions and a deleted transient build dependency capable of executing malicious code during Cargo builds.