Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Description
On August 20, 2026, malicious versions of three Rust crates ([email protected], [email protected], and [email protected]) were published to crates.io. These crates included a typosquatted dependency named proc-macro1, whose build script downloads and executes a remote binary during compilation. This binary installs a backdoor that communicates with command and control servers over HTTPS, exfiltrates host and browser data, enumerates installed applications, and persists via common OS mechanisms such as Registry Run keys, LaunchAgents, or systemd user services. The attack infrastructure overlaps with North Korean threat actor operations, notably the Mastra campaign and previous DPRK-linked supply chain attacks. No official remediation guidance is currently available.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This supply chain attack involved publishing malicious versions of three Rust crates to crates.io that introduced a typosquatted dependency named proc-macro1. The malicious build script downloads and executes a remote binary at compile time, deploying a backdoor capable of beaconing to C2 servers over HTTPS, exfiltrating system and browser data, enumerating installed applications, and establishing persistence through multiple OS-specific methods. The campaign infrastructure shows significant overlap with North Korean threat actor STARDUST CHOLLIMA, including shared command and control endpoint patterns with the Mastra campaign and IP addresses used in the axios npm attack.
Potential Impact
The malicious crates enable attackers to gain persistent backdoor access to affected systems, allowing exfiltration of sensitive host and browser data, enumeration of installed applications, and persistence via Registry Run keys, LaunchAgents, or systemd user services. This compromises the confidentiality and integrity of affected systems and any sensitive data stored or accessed on them. The supply chain nature of the attack increases the risk of widespread impact among Rust developers and users who consume these crates.
Defensive Guidance
No official patch or remediation guidance is currently provided. Patch status is not yet confirmed—users should consult vendor advisories or crates.io announcements for updates. Until clean versions are available, users should avoid using the affected crate versions and verify dependencies for typosquatting or unexpected build scripts. Monitoring for indicators of compromise such as the listed domain (hwsrv-798836.hostwindsdns.com) and associated file hashes may assist in detection. Rebuilding projects with verified clean dependencies is recommended once clean versions are released.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns"]
- Adversary
- STARDUST CHOLLIMA
- Pulse Id
- 6a8775e93b9ffe6d9c526c90
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainhwsrv-798836.hostwindsdns.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash25ad700976873c76af785cb99b33c48db7df8b81f21d1e9e06b3676b9a9373ae | — | |
hash61198155da51b838772eecf5bfaac6cbc4dcc388dccc56658fc28a8e831b34d4 | — | |
hashb5c1b5b0763a8809a644a8f92224653f0aca623a98eecc714d27f74b80fbe436 | — | |
hashf22e3e01e38bcdf001f0d15a2dbfdec5a1cf8eff | — | |
hashf4767ad92cb61401fd69139cade563501c39b991 | — | |
hashfc0fdb978eac72f4484b48db058e4473f1bc516e | — | |
hashff7e20cf642346bf893f1eca808df82035bb53d0 | — |
Threat ID: 6a88904eacd9273b497ff252
Added to database: 08/21/2026, 17:52:14 UTC
Last enriched: 09/11/2026, 02:33:52 UTC
Last updated: 10/03/2026, 22:53:17 UTC
Views: 121
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.