Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack

2026-08-20 Aikido

https://www.aikido.dev/blog/two-popular-rust-crates-arrayref-and-append-only-vec-compromised-in-supply-chain-attack

Thumbnail for Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack

An unidentified attacker compromised versions of the popular Rust crates `arrayref` and `append-only-vec` by injecting a dependency on the typosquatted `proc-macro1` package. Its Cargo build script downloads and executes cross-platform malware that steals Chromium browser credentials and wallet-extension data, establishes macOS LaunchAgent persistence, and supports remote shell commands. Aikido identified `23.254.165.112` as the payload-delivery and command-and-control host and published SHA-256 hashes for Linux and macOS payloads.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 74d3447e7cf99c99ea01a16332ec274… 2026-08-20 2026-08-20
HASH 408ef22050ffc5a67e005802809026b… 2026-08-20 2026-08-20
URL https://23.254.165.112:443/4989… 2026-08-20 2026-08-20
URL https://23.254.165.112:9089/ 2026-08-20 2026-08-20
IPv4 23.254.165.112 2026-08-20 2026-08-20

Related Reports

« Back