RUSTSEC-2026-0260None▾ Sunlit`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A new version of the arrayref crate was published with a direct dependency
on proc-macro1, which would execute a malicious build script.
This compromised version was published on 2026-08-20 and removed approximately 86 minutes later, with no evidence of actual usage.
arrayref >= 0.3.10-0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.