OVERCLOCK.news
developer

Supply chain attack on arrayref

What happened On 2026-08-20 at 7:15 UTC we got a report that the proc-macro1 crate was malicious.

BlueskyXRedditMail
Why am I seeing this Ranked on source trust — Rust

It ranks mainly on source trust: Rust is the most reliable outlet we track on this subject, and is the only one on the story so far.

The classifier could not identify the subject from the text, so the section was inherited from the source feed. We do not summarise what we cannot identify — this one links straight out.

Link-outLink-out, because the subject could not be identified from the text. Link-out means we point at the publisher and say nothing of our own.

Blended score 0.385 — every figure below is computed, none of it is editorial.
FactorWeightScore ContributionWhere it came from
Corroboration 0.35 0.39 +0.135 35% 1 independent org on the story. Tier-3 aggregators never corroborate — they can show something is circulating, never that it is true.
Source trustleads 0.25 1.00 +0.250 65% Rust is the highest-trust source on this story and is first-party — the organisation announcing its own news. Trust is taken from the best source, not averaged.
Pickup rate 0.20 0.00 +0.000 0% One counted organisation, so there is no spread to measure — nothing has picked this up to set a rate.
Freshness 0.20 0.00 +0.000 0% Halves every 10 hours from the newest item on the story. This is the only factor that rewards a story for nothing more than being recent.

Corroboration counts distinct organisations, once each, and only from tiers 1 and 2. Freshness halves every 10 hours, so this ranking is a snapshot and will differ at the next build.

Read the full article at Rust →

What happened

What happened On 2026-08-20 at 7:15 UTC we got a report that the proc-macro1 crate was malicious. The Rust Security Response Team verified this to be the case: the crate had a build script that was downloading a malicious payload. This crate proc-macro1 and others like it ( proc-macro-en, aovine, arone, aronenao, tinymember ) have been deleted. Furthermore, we discovered that the popular arrayref crate had recently been republished and made to depend on this crate, with the most recent versions yanked. We have removed the malicious version and unyanked the maliciously-yanked versions. Other crates by that author ( internment, append-only-vec ) were also affected so we have done the same for those, and locked the account as a precaution.

1independent orgs
39story score
0velocity
100source trust
215passes seen

How this story arrived

Ordered by when each source was first observed, which is what the velocity figure is computed from. Publishers backdate; observed order does not.

  1. 01 Rustfirst-party first seen Supply chain attack on arrayref

Overclock clusters coverage from independent sources and grades it automatically. The figures above are computed, not editorial. This page summarises and links to reporting by the outlets named — follow the links for the original work.