2026-10-11 17:10 UTC

Investigation and maintainer response will determine the exposure from compromised Arrayref 0.3.10 and 0.3.11 builds and whether Rust ecosystem remediation fully removes the malicious dependency path.

state: expiredheat: lowuncertainty: highknownscott: lowsoftware-supply-chain rust-security build-system-securityArrayrefcrates.ioRustSec

What is this?

Arrayref versions 0.3.10 and 0.3.11 were reportedly compromised on crates.io; the incident report says 0.3.10 introduced a dependency on the typosquatted `proc-macro1` 1.0.107 crate. This is a Rust software-supply-chain incident involving a malicious dependency introduced through the build ecosystem. The supplied search snippets establish that crates.io and RustSec remove and document malicious crates generally, but they do not independently confirm Arrayref’s precise exposure, the maintainer’s response, or that remediation fully eliminated this dependency path.

Why it matters to Scott

This is a Rust-specific instance of dependency risk already covered by Scott’s Sovereign Software Assurance requirement that dependencies be explicit, auditable, and governable. It adds no established exposure finding or remediation result that would yet change his position or builds; the radar already tracks the broader pattern on `software-supply-chain`.
ip:framework.sovereign-software-assuranceradar:concept.software-supply-chain
queries asked of Scott's wikis
  • dependency trust in AI coding-agent builds
  • lockfiles provenance and reproducible builds
  • proc-macro and build-script security boundaries
  • software supply-chain controls for generated code
  • agent harness dependency auditing
  • package registry typosquatting defenses

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (5) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnArrayref v0.3.10 and v0.3.11 compromised on crates.iostevefan199910
🟧 echo.github ⭐Primary incident report filed at 07:54 UTC. It reports that arrayref 0.3.10 added a dependency on typosquatted proc-macro1 1.0.107, whose bujhobern——
🟧 hnMalicious Version of ArrayRef (0.3.10) PublishedJohn2383210
🟧 hnRust arrayref 0.3.10 crate installs malwarejedisct110
🟧 hnMalicious Rust Crate Arrayref Runs a Build-Time Payloadabhisek549493

Interpretation history

Decision trace