arrayref crates.io account published build-script dropper dependency

2026-08-20 Isotope13

https://isotope13.ai/compendium/2026/arrayref/

Thumbnail for arrayref crates.io account published build-script dropper dependency

Attackers used a compromised crates.io maintainer account to publish malicious versions of arrayref, internment, and append-only-vec that pulled in a typosquatted dependency whose build script executed during compilation. The second stage harvested browser credentials, established cross-platform persistence, and communicated with Hostwinds infrastructure, while arrayref 0.3.10 accumulated 2,285 downloads before removal. Wiz identified infrastructure and beaconing overlaps with the Sapphire Sleet-attributed Mastra compromise and the UNC1069-linked axios attack, but the source stops short of attributing the arrayref operation itself to DPRK actors.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://23.254.165.112:9089/ 2026-08-20 2026-08-20
DOMAIN hwsrv-798836.hostwindsdns.com 2026-08-20 2026-08-20
IPv4 23.254.167.107 2026-08-20 2026-08-20
IPv4 23.254.165.112 2026-08-20 2026-08-20
IPv4 23.254.167.216 2025-01-14 2026-08-20

Related Actors

Related Reports

« Back