Rust developers hit by supply-chain attack on arrayref crate

Attackers hijacked a maintainer account and slipped credential-stealing malware into three popular Rust libraries during a 1.5-hour window on August 20.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A developer's workspace with multiple monitors showing code repositories and package manager windows, with one screen displaying a compromised file alert overla
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Attackers compromised the maintainer account behind three Rust libraries (arrayref, append-only-vec and internment) on August 20, publishing malicious versions within a 23-minute window.
  • The arrayref package has been downloaded over 245 million times in total; in the past 90 days alone it recorded more than 53 million downloads.
  • The malware ran automatically at build time, then stole browser passwords and set itself to survive reboots across Windows, macOS and Linux.
  • Wiz researchers say the attack's infrastructure overlaps with North Korean supply-chain campaigns including Mastra and axios.
  • Developers who pulled the poisoned versions during the roughly 1.5-hour exposure window should treat their machines as breached.

Hackers broke into the account of a Rust library maintainer and pushed booby-trapped updates that executed malware the moment developers compiled their code. Rust is a popular programming language; the libraries (called "crates") are shared building blocks that thousands of projects depend on.

The poisoned releases, first reported by BleepingComputer, were arrayref 0.3.10, append-only-vec 0.1.9 and internment 0.8.7, all under the same maintainer account. Arrayref alone has racked up more than 245 million lifetime downloads and is pulled in by cryptography tools, blockchain libraries and Rust GUI frameworks including blake3, egui and projects tied to Ethereum and Solana.

How did the attackers pull it off?

They hid the attack inside a fake dependency. The real library code was left untouched; the attackers wired in a package called proc-macro1, a look-alike of the legitimate proc-macro2 crate. This technique is called typosquatting: registering a name almost identical to a trusted one.

Inside proc-macro1 was a file named build.rs that Rust runs automatically during compilation. It rebuilt the payload from base64-encoded fragments (a way to disguise code as harmless-looking text) and delivered a binary matched to the developer's operating system. On Unix machines the malware dropped /tmp/rust-setup and ran it as a background process; Windows got %TEMP%\rust-setup.ps1, kept alive by a hidden script host.

What did the malware actually do?

It stole credentials and called home. Wiz's analysis found the second-stage payload pulled login details from Chrome and Brave by reading their local SQLite password databases. Edge was also targeted.

Persistence varied by platform: a Registry Run key on Windows, a LaunchAgent on macOS, a systemd service on Linux. All variants phoned out to 23.254.165.112 on ports 9089 and 443.

Timeline of the attack

Time (UTC, Aug 20) Event
01:17 Fake GitHub account impersonating Rust developer David Tolnay created
01:55 Benign proc-macro1@1.0.106 published as bait
07:11 Malicious proc-macro1@1.0.107 published
07:15 arrayref 0.3.10 published; versions 0.3.5 through 0.3.9 removed
08:03 crates.io deletes proc-macro1
08:41 crates.io pulls arrayref 0.3.10

The window ran roughly 1.5 hours. This kind of account-takeover-plus-typosquat combination has become a reliable pattern; our 31 July report on Arch Linux's package freeze documented almost identical credential-stealer behaviour spreading through community-maintained repositories.

Should you worry?

If you ran cargo build against any of those versions on August 20 between 07:15 and 08:41 UTC, yes. Check your Cargo.lock for the affected version numbers, look for dropped files at /tmp/rust-setup or %TEMP%\rust-setup.ps1, and review network logs for traffic to 23.254.165.112.

Confirmed compromise means rotating everything the machine could touch: cloud tokens, CI secrets, code-signing keys. Rebuild from a clean backup rather than attempting in-place cleanup. Unaffected projects should pin a known-good version of the three crates until the maintainer account situation is resolved. Full indicators of compromise are in analyses published by StepSecurity, SafeDep and Aikido, each independently.

The North Korea attribution is worth watching but shouldn't distract from the immediate job. Whatever the actor, the technique is cheap and repeatable, and the Rust ecosystem's trust in crates.io is what made it work.

© 2026 Threat Vectr