Malicious Rust crate arrayref runs a build-time payload
A backdoored release of the widely-used `arrayref` crate ran attacker code at build time via a proc-macro, harvesting credentials from any machine that compiled it. The Rust Security Response WG has yanked the release; the writeup traces exactly how the build-time payload worked.