Security & supply chainThe arrayref takeover is the crates.io threat model, not a surprise
A DevOps.com report says attackers took over the maintainer account behind the popular Rust crate arrayref and pushed four additional attacker-owned crates carrying information-stealing malware. The more useful question for CI/CD teams is what your build farm did with that code before anyone noticed.