Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper

2026-08-20 Step Security

https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack

Thumbnail for Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper

An attacker compromised a Rust maintainer account and poisoned `arrayref 0.3.10`, `internment 0.8.7`, and `append-only-vec 0.1.9` with a dependency on a build-time dropper. Compiling an affected dependency downloaded and executed a second-stage payload from `23.254.165.112:9089` while allowing the build to finish successfully. Organizations that resolved the malicious releases during the August 20 exposure window should treat their build systems as compromised, rotate accessible credentials, purge caches, and rebuild artifacts from clean sources.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2026-08-20 2026-08-20
URL https://23.254.165.112:9089/ 2026-08-20 2026-08-20
DOMAIN hwsrv-798836.hostwindsdns.com 2026-08-20 2026-08-20
IPv4 23.254.167.107 2026-08-20 2026-08-20
IPv4 23.254.165.112 2026-08-20 2026-08-20
HASH b5c1b5b0763a8809a644a8f92224653… 2026-08-20 2026-08-20
HASH 61198155da51b838772eecf5bfaac6c… 2026-08-20 2026-08-20
HASH 25ad700976873c76af785cb99b33c48… 2026-08-20 2026-08-20
IPv4 23.254.167.216 2025-01-14 2026-08-20

Related Reports

« Back