Hackers poison arrayref Rust crate to push infostealer malware

Hackers poison arrayref Rust crate to push infostealer malware

Hackers compromised the account of the maintainer behind the widely used Rust crate arrayref to introduce malware that runs on developer systems at compile time.

Within a 23-minute window, the attacker also poisoned two other checkouts, append-only-vec and internment, in the same supply chain attack.

The arrayref box is a popular Rust library with more than 53 million downloads in the last 90 days that is used by cryptography, graphing, and blockchain tools.

image

A report from application security company StepSecurity notes that the malicious versions of Rust crate are arrayref 0.3.10, append-only-vec 0.1.9, and internment 0.8.7, all maintained by the same account.

The hacker injected a dependency on a package called proc-macro1, a typosquat impersonation of the popular proc-macro2 box, while keeping the rest of the upstream source code completely unchanged.

According to the researchers, a script in proc-macro1 called “build.rs” runs automatically during compilation, reconstructing its infrastructure from base64-encoded fragments and selecting a payload that matches the host OS (Linux x86-64, Windows x86-64, macOS x86-64, and macOS ARM64).

StepSecurity says the attacker also published multiple versions of four sammy crates (aovine, arone, aronenao, tinymember) that were removed from crates.io.

On Unix systems, the malware writes to /tmp/rust-setup, marks it as executable, and runs it as a separate process.

On Windows it creates %TEMP%\rust-setup.ps1 and uses a hidden wscript.exe and VBS launcher to keep the process running.

The payload receives an address as an argument, which is assumed to be a command-control address.

According to an analysis by cloud security company Wiz, the capabilities of the second stage include exfiltrating host information and credentials.

The say the researchers that the malware collects credentials from Google Chrome, Brave and Edge browsers by querying SQLite login databases.

Persistence is established through the registry run key on Windows, LaunchAgent on macOS, and systemd on Linux.

Schedule and impact

The potential impact of this supply chain attack is significant, as arrayref alone has more than 245 million lifetime downloads, while the total for append-only-vec and internment is nearly 19 million installs.

Projects using arrayref include blake3, Rust GUI frameworks such as egui, eframe, and iced, and components used in Ethereum and Solana.

The attack began at 01:17 UTC on August 20, when a GitHub account was created impersonating prominent Rust developer David Tolnay, followed by a similar account on the crates.io registry.

At 01:55 the attacker published proc-macro1@1.0.106, a benign copy of proc-macro2, followed by a malicious update via version 1.0.107 published at 7:11.

At 07:15 arrayref 0.3.10 was posted via the legitimate account of druundy (David Roundy), while versions 0.3.5 to 0.3.9 were removed, potentially to force installation of the malicious release.

The incident was reported at 07:54. Crates.io deleted proc-macro1 at 08:03 and removed arrayref 0.3.10 from the index at 08:41.

Cyber ​​Security Companies Step Security, SafeDepand Aikido each has published a technical analysis of the supply chain attack and shared indicators of compromise.

Wiz researchers note that “the campaign’s infrastructure overlaps with recent DPRK (North Korea) supply chain attacks, including Mastra and axios.”

Developers who have installed either during the exposure window of nearly 1.5 hours must accept a trade-off.

Recommended checks include looking in Cargo.lock files, looking for dropped files, and looking at traffic to 23.254.165(.)112 on ports 9089 and 443.

When a compromise is confirmed, it is recommended to rotate all available credentials, CI tokens, signing keys, and other secrets and restore the environment from safe backups.

Clean projects should commit a known safe version of the affected dependencies until the maintainer situation is clarified and resolved.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *