A security incident has been reported regarding the Rust crate `arrayref` version 0.3.10. It was compromised by a typosquatted version of `proc-macro1`, which executes a remote payload when the crate is built. The malicious code was introduced via a dependency added to `arrayref`, causing any project that compiled it to run the payload. The incident has drawn significant attention due to the foundational nature of `arrayref`, with around 245 million downloads, affecting various projects in the Rust ecosystem.
Users are advised to check their lockfiles and take remediation steps if they are found to be affected. The attack involved a series of quick actions, replicating accounts to impersonate legitimate authors and publishing altered crate versions.