Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Hackers poison arrayref Rust crate to push infostealer malware

0
Critical
Malwaremalware
Published: 08/20/2026 (08/20/2026, 17:53:52 UTC)
Source: Bleeping Computer

Description

A supply-chain attack compromised the maintainer account of the popular Rust crate arrayref, introducing malware that executed during compilation. The attacker also poisoned two other crates, append-only-vec and internment, within a short window. The malicious code included a typosquatted dependency that executed a payload tailored to the host OS, capable of stealing credentials and establishing persistence. The attack affected widely used Rust projects, including cryptography and blockchain tools. The compromised versions were quickly removed from the registry after discovery. Developers who used these versions during the exposure window should assume compromise and take remediation steps.

Affected software

Affected versions
=0.3.10=0.1.9=0.8.7

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 18:07:24 UTC

Technical Analysis

Attackers compromised the maintainer account of the Rust crate arrayref and introduced malware in version 0.3.10, alongside poisoned versions of append-only-vec 0.1.9 and internment 0.8.7. The malware was delivered via a typosquatted dependency named proc-macro1, impersonating proc-macro2, which executed a build script during compilation. This script reconstructed its payload from base64 fragments and deployed OS-specific infostealer malware targeting Linux, Windows, and macOS systems. The malware exfiltrated credentials from browsers, established persistence via system mechanisms (Registry Run key, LaunchAgent, systemd), and communicated with a command-and-control server. The attack lasted approximately 1.5 hours before detection and removal of malicious packages from crates.io. The infrastructure overlaps with known DPRK supply-chain attacks. Developers using affected versions should assume compromise and rotate credentials and secrets.

Potential Impact

The attack potentially compromised developer systems compiling the affected Rust crates, leading to credential theft from browsers and persistent malware presence. Given arrayref's extensive use in cryptography, graphics, blockchain, and major Rust projects, the impact is significant. The attacker gained access to sensitive credentials and could maintain persistence, increasing risk of further compromise. The supply-chain nature means downstream projects and users depending on these crates may also be affected if they used the malicious versions during the exposure window.

Defensive Guidance

The malicious versions (arrayref 0.3.10, append-only-vec 0.1.9, internment 0.8.7) were removed from crates.io shortly after discovery. Developers who installed these versions during the exposure window should assume compromise. Recommended actions include searching Cargo.lock files for these versions, checking for dropped malicious files, reviewing network traffic to the identified command-and-control IP and ports, rotating all credentials, CI tokens, signing keys, and secrets, and rebuilding environments from trusted backups. Projects should pin dependencies to known safe versions until the maintainer situation is resolved. No official patch is indicated; remediation relies on removal and credential rotation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.93,"severitySource":"default","classifier":"rss-v2"}

Threat ID: 6a874251acd9273b49f69a6b

Added to database: 08/20/2026, 18:07:13 UTC

Last enriched: 08/20/2026, 18:07:24 UTC

Last updated: 08/20/2026, 22:00:05 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses