Hackers compromise the maintainer account behind the popular Rust crate arrayref to inject malware that runs on developers' systems during compilation. In a 23-minute window, the attacker also poisons two other crates maintained by the same account, append-only-vec and internment. The malicious releases include arrayref 0.3.10, append-only-vec