Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack
2026-08-20 • Aikido •
An unidentified attacker compromised versions of the popular Rust crates `arrayref` and `append-only-vec` by injecting a dependency on the typosquatted `proc-macro1` package. Its Cargo build script downloads and executes cross-platform malware that steals Chromium browser credentials and wallet-extension data, establishes macOS LaunchAgent persistence, and supports remote shell commands. Aikido identified `23.254.165.112` as the payload-delivery and command-and-control host and published SHA-256 hashes for Linux and macOS payloads.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 74d3447e7cf99c99ea01a16332ec274… | 2026-08-20 | 2026-08-20 |
| HASH | 408ef22050ffc5a67e005802809026b… | 2026-08-20 | 2026-08-20 |
| URL | https://23.254.165.112:443/4989… | 2026-08-20 | 2026-08-20 |
| URL | https://23.254.165.112:9089/ | 2026-08-20 | 2026-08-20 |
| IPv4 | 23.254.165.112 | 2026-08-20 | 2026-08-20 |
Related Reports
Shares tag: arrayref • Shares 3 IOCs • Published within a week
2026-08-20 •
76% Match
Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper
Step Security
Shares tag: arrayref • Shares 2 IOCs • Published within a week
Shares tag: arrayref • Published within a week