kirit0s.bsky.social
@kirit0s.bsky.social
Reposted
⚠️ A few hours ago, a malicious crate was discovered on crates.​io which spread as a dependency of `arrayref` and some other crates, likely due to compromised credentials. The affected versions have been deleted.

For details and how to see if you are impacted, see: blog.rust-lang.org/2026/08/20/s...
Supply chain attack on arrayref | Rust Blog
Empowering everyone to build reliable and efficient software.
blog.rust-lang.org
August 20, 2026 at 10:29 AM
Reposted
Wild, but expected. AUR (Arch Linux User Repository) pushes completely disabled atm due to influx of malware.

I predicted widespread temporary shutdowns of major package repositories earlier this year. looks like it's happening!
August 2, 2026 at 5:47 PM