A malicious version of the Rust crate arrayref was released on crates.io, which included a build-time payload that downloaded and ran a remote binary. The malicious code was introduced through a dependency on a typosquatted crate called proc-macro1. The crates.io team has since removed the malicious versions. The incident highlights the risks of supply chain attacks in the Rust ecosystem.