Hackers poison arrayref Rust crate to push infostealer malware
A supply-chain attack compromised the maintainer account of the popular Rust crate arrayref, introducing malware that executed during compilation. The attacker also poisoned two other crates, append-only-vec and internment, within a short window. The malicious code included a typosquatted dependency that executed a payload tailored to the host OS, capable of stealing credentials and establishing persistence. The attack affected widely used Rust projects, including cryptography and blockchain tools. The compromised versions were quickly removed from the registry after discovery. Developers who used these versions during the exposure window should assume compromise and take remediation steps.
AI Analysis
Technical Summary
Attackers compromised the maintainer account of the Rust crate arrayref and introduced malware in version 0.3.10, alongside poisoned versions of append-only-vec 0.1.9 and internment 0.8.7. The malware was delivered via a typosquatted dependency named proc-macro1, impersonating proc-macro2, which executed a build script during compilation. This script reconstructed its payload from base64 fragments and deployed OS-specific infostealer malware targeting Linux, Windows, and macOS systems. The malware exfiltrated credentials from browsers, established persistence via system mechanisms (Registry Run key, LaunchAgent, systemd), and communicated with a command-and-control server. The attack lasted approximately 1.5 hours before detection and removal of malicious packages from crates.io. The infrastructure overlaps with known DPRK supply-chain attacks. Developers using affected versions should assume compromise and rotate credentials and secrets.
Potential Impact
The attack potentially compromised developer systems compiling the affected Rust crates, leading to credential theft from browsers and persistent malware presence. Given arrayref's extensive use in cryptography, graphics, blockchain, and major Rust projects, the impact is significant. The attacker gained access to sensitive credentials and could maintain persistence, increasing risk of further compromise. The supply-chain nature means downstream projects and users depending on these crates may also be affected if they used the malicious versions during the exposure window.
Mitigation Recommendations
The malicious versions (arrayref 0.3.10, append-only-vec 0.1.9, internment 0.8.7) were removed from crates.io shortly after discovery. Developers who installed these versions during the exposure window should assume compromise. Recommended actions include searching Cargo.lock files for these versions, checking for dropped malicious files, reviewing network traffic to the identified command-and-control IP and ports, rotating all credentials, CI tokens, signing keys, and secrets, and rebuilding environments from trusted backups. Projects should pin dependencies to known safe versions until the maintainer situation is resolved. No official patch is indicated; remediation relies on removal and credential rotation.
Hackers poison arrayref Rust crate to push infostealer malware
Description
A supply-chain attack compromised the maintainer account of the popular Rust crate arrayref, introducing malware that executed during compilation. The attacker also poisoned two other crates, append-only-vec and internment, within a short window. The malicious code included a typosquatted dependency that executed a payload tailored to the host OS, capable of stealing credentials and establishing persistence. The attack affected widely used Rust projects, including cryptography and blockchain tools. The compromised versions were quickly removed from the registry after discovery. Developers who used these versions during the exposure window should assume compromise and take remediation steps.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Attackers compromised the maintainer account of the Rust crate arrayref and introduced malware in version 0.3.10, alongside poisoned versions of append-only-vec 0.1.9 and internment 0.8.7. The malware was delivered via a typosquatted dependency named proc-macro1, impersonating proc-macro2, which executed a build script during compilation. This script reconstructed its payload from base64 fragments and deployed OS-specific infostealer malware targeting Linux, Windows, and macOS systems. The malware exfiltrated credentials from browsers, established persistence via system mechanisms (Registry Run key, LaunchAgent, systemd), and communicated with a command-and-control server. The attack lasted approximately 1.5 hours before detection and removal of malicious packages from crates.io. The infrastructure overlaps with known DPRK supply-chain attacks. Developers using affected versions should assume compromise and rotate credentials and secrets.
Potential Impact
The attack potentially compromised developer systems compiling the affected Rust crates, leading to credential theft from browsers and persistent malware presence. Given arrayref's extensive use in cryptography, graphics, blockchain, and major Rust projects, the impact is significant. The attacker gained access to sensitive credentials and could maintain persistence, increasing risk of further compromise. The supply-chain nature means downstream projects and users depending on these crates may also be affected if they used the malicious versions during the exposure window.
Defensive Guidance
The malicious versions (arrayref 0.3.10, append-only-vec 0.1.9, internment 0.8.7) were removed from crates.io shortly after discovery. Developers who installed these versions during the exposure window should assume compromise. Recommended actions include searching Cargo.lock files for these versions, checking for dropped malicious files, reviewing network traffic to the identified command-and-control IP and ports, rotating all credentials, CI tokens, signing keys, and secrets, and rebuilding environments from trusted backups. Projects should pin dependencies to known safe versions until the maintainer situation is resolved. No official patch is indicated; remediation relies on removal and credential rotation.
Technical Details
- Classification
- {"confidence":0.93,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a874251acd9273b49f69a6b
Added to database: 08/20/2026, 18:07:13 UTC
Last enriched: 08/20/2026, 18:07:24 UTC
Last updated: 08/20/2026, 22:00:05 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.