arrayref crates.io account published build-script dropper dependency
2026-08-20 • Isotope13 •
Attackers used a compromised crates.io maintainer account to publish malicious versions of arrayref, internment, and append-only-vec that pulled in a typosquatted dependency whose build script executed during compilation. The second stage harvested browser credentials, established cross-platform persistence, and communicated with Hostwinds infrastructure, while arrayref 0.3.10 accumulated 2,285 downloads before removal. Wiz identified infrastructure and beaconing overlaps with the Sapphire Sleet-attributed Mastra compromise and the UNC1069-linked axios attack, but the source stops short of attributing the arrayref operation itself to DPRK actors.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://23.254.165.112:9089/ | 2026-08-20 | 2026-08-20 |
| DOMAIN | hwsrv-798836.hostwindsdns.com | 2026-08-20 | 2026-08-20 |
| IPv4 | 23.254.167.107 | 2026-08-20 | 2026-08-20 |
| IPv4 | 23.254.165.112 | 2026-08-20 | 2026-08-20 |
| IPv4 | 23.254.167.216 | 2025-01-14 | 2026-08-20 |