Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper
2026-08-20 • Step Security •
https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack
An attacker compromised a Rust maintainer account and poisoned `arrayref 0.3.10`, `internment 0.8.7`, and `append-only-vec 0.1.9` with a dependency on a build-time dropper. Compiling an affected dependency downloaded and executed a second-stage payload from `23.254.165.112:9089` while allowing the build to finish successfully. Organizations that resolved the malicious releases during the August 20 exposure window should treat their build systems as compromised, rotate accessible credentials, purge caches, and rebuild artifacts from clean sources.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2026-08-20 | 2026-08-20 | |
| URL | https://23.254.165.112:9089/ | 2026-08-20 | 2026-08-20 |
| DOMAIN | hwsrv-798836.hostwindsdns.com | 2026-08-20 | 2026-08-20 |
| IPv4 | 23.254.167.107 | 2026-08-20 | 2026-08-20 |
| IPv4 | 23.254.165.112 | 2026-08-20 | 2026-08-20 |
| HASH | b5c1b5b0763a8809a644a8f92224653… | 2026-08-20 | 2026-08-20 |
| HASH | 61198155da51b838772eecf5bfaac6c… | 2026-08-20 | 2026-08-20 |
| HASH | 25ad700976873c76af785cb99b33c48… | 2026-08-20 | 2026-08-20 |
| IPv4 | 23.254.167.216 | 2025-01-14 | 2026-08-20 |