Skip to main content

Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns

0
Medium
Published: 08/20/2026 (08/20/2026, 21:47:21 UTC)
Source: AlienVault OTX General

Description

On August 20, 2026, malicious versions of three Rust crates ([email protected], [email protected], and [email protected]) were published to crates.io. These crates included a typosquatted dependency named proc-macro1, whose build script downloads and executes a remote binary during compilation. This binary installs a backdoor that communicates with command and control servers over HTTPS, exfiltrates host and browser data, enumerates installed applications, and persists via common OS mechanisms such as Registry Run keys, LaunchAgents, or systemd user services. The attack infrastructure overlaps with North Korean threat actor operations, notably the Mastra campaign and previous DPRK-linked supply chain attacks. No official remediation guidance is currently available.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 02:33:52 UTC

Technical Analysis

This supply chain attack involved publishing malicious versions of three Rust crates to crates.io that introduced a typosquatted dependency named proc-macro1. The malicious build script downloads and executes a remote binary at compile time, deploying a backdoor capable of beaconing to C2 servers over HTTPS, exfiltrating system and browser data, enumerating installed applications, and establishing persistence through multiple OS-specific methods. The campaign infrastructure shows significant overlap with North Korean threat actor STARDUST CHOLLIMA, including shared command and control endpoint patterns with the Mastra campaign and IP addresses used in the axios npm attack.

Potential Impact

The malicious crates enable attackers to gain persistent backdoor access to affected systems, allowing exfiltration of sensitive host and browser data, enumeration of installed applications, and persistence via Registry Run keys, LaunchAgents, or systemd user services. This compromises the confidentiality and integrity of affected systems and any sensitive data stored or accessed on them. The supply chain nature of the attack increases the risk of widespread impact among Rust developers and users who consume these crates.

Defensive Guidance

No official patch or remediation guidance is currently provided. Patch status is not yet confirmed—users should consult vendor advisories or crates.io announcements for updates. Until clean versions are available, users should avoid using the affected crate versions and verify dependencies for typosquatting or unexpected build scripts. Monitoring for indicators of compromise such as the listed domain (hwsrv-798836.hostwindsdns.com) and associated file hashes may assist in detection. Rebuilding projects with verified clean dependencies is recommended once clean versions are released.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns"]
Adversary
STARDUST CHOLLIMA
Pulse Id
6a8775e93b9ffe6d9c526c90

Indicators of Compromise

Domain

ValueDescriptionCopy
domainhwsrv-798836.hostwindsdns.com
—

Hash

ValueDescriptionCopy
hash25ad700976873c76af785cb99b33c48db7df8b81f21d1e9e06b3676b9a9373ae
—
hash61198155da51b838772eecf5bfaac6cbc4dcc388dccc56658fc28a8e831b34d4
—
hashb5c1b5b0763a8809a644a8f92224653f0aca623a98eecc714d27f74b80fbe436
—
hashf22e3e01e38bcdf001f0d15a2dbfdec5a1cf8eff
—
hashf4767ad92cb61401fd69139cade563501c39b991
—
hashfc0fdb978eac72f4484b48db058e4473f1bc516e
—
hashff7e20cf642346bf893f1eca808df82035bb53d0
—

Threat ID: 6a88904eacd9273b497ff252

Added to database: 08/21/2026, 17:52:14 UTC

Last enriched: 09/11/2026, 02:33:52 UTC

Last updated: 10/03/2026, 22:53:17 UTC

Views: 121

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses