[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-rust-crate-arrayref-proc-macro1-hides-a-build-time-payload":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},5761,"rust-crate-arrayref-proc-macro1-hides-a-build-time-payload","Rust Crate arrayref-proc-macro1 Hides a Build-Time Payload","Security researchers at SafeDep found a Rust crate posing as the popular arrayref library that executes malicious code the moment you build your project.","A Rust package impersonating the popular arrayref crate has been caught running code the moment a project builds, not after.\n\nSupply-chain security researchers at SafeDep identified the package as arrayref-proc-macro1 on the crates.io registry, its name a near-match for arrayref, a legitimate and widely used crate for casting byte slices into fixed-size arrays. According to [SafeDep's research](https:\u002F\u002Fsafedep.io\u002Farrayref-proc-macro1-rust-build-time-malware\u002F), published August 20, 2026, the package carries what the researchers call a build-time payload - code that executes as part of compiling a project rather than waiting for the finished binary to run. Beyond identifying the package and its build-time behavior, further technical detail was not immediately available. The discovery quickly drew attention from developers monitoring open-source security research.\n\nTyposquatting on package registries is a well-worn con - fake libraries riding a popular name's coattails have hit npm and PyPI for years. What is different in Rust's case is timing: crates.io allows procedural-macro packages to compile and execute as part of the build itself, so a malicious dependency does not need anyone to ever run the finished program to act.\n\nRust's ecosystem is younger and smaller than npm's, which has limited how often it shows up in this kind of research - arrayref-proc-macro1 is a reminder that smaller doesn't mean safer, just less examined so far.","[\"rust\",\"supply-chain-security\",\"crates.io\",\"malware\"]","2026-08-20T13:23:12.000Z","2026-08-20T14:06:52.822Z","2026-08-20T14:07:04.695Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"Pull the actual SafeDep writeup and rewrite using only verifiable facts — name the real malicious crate (e.g. arrayref-proc-macro1 per the source URL) instead of vaguely alluding to it, cite\u002Flink the SafeDep research explicitly, and cut the specific mechanism\u002Fblast-radius\u002Ftooling-blind-spot claims that aren't supported by the thin source material provided (just an HN headline and URL).","resolved","security",[32,33,34,35],"rust","supply-chain-security","crates.io","malware",[37],{"name":38,"url":39},"Hacker News","https:\u002F\u002Fsafedep.io\u002Farrayref-proc-macro1-rust-build-time-malware\u002F",0,{"sections":42},[43,48,52,57,62,67,72,77,82,87,92,97,102,107],{"name":44,"slug":45,"count":46,"latest_published_at":47},"AI","ai",3298,"2026-08-20T15:45:55.000Z",{"name":49,"slug":30,"count":50,"latest_published_at":51},"Security",442,"2026-08-20T13:55:00.000Z",{"name":53,"slug":54,"count":55,"latest_published_at":56},"Policy","policy",211,"2026-08-20T10:47:43.000Z",{"name":58,"slug":59,"count":60,"latest_published_at":61},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":63,"slug":64,"count":65,"latest_published_at":66},"Hardware","hardware",141,"2026-08-20T11:20:00.000Z",{"name":68,"slug":69,"count":70,"latest_published_at":71},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":73,"slug":74,"count":75,"latest_published_at":76},"Science","science",91,"2026-08-20T10:01:48.000Z",{"name":78,"slug":79,"count":80,"latest_published_at":81},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":83,"slug":84,"count":85,"latest_published_at":86},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":88,"slug":89,"count":90,"latest_published_at":91},"Startups","startups",47,"2026-08-19T19:13:46.000Z",{"name":93,"slug":94,"count":95,"latest_published_at":96},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":98,"slug":99,"count":100,"latest_published_at":101},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":103,"slug":104,"count":105,"latest_published_at":106},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":108,"slug":109,"count":110,"latest_published_at":111},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]