arrayref

#arrayref • 2026-08

On August 20, 2026, attackers used a compromised crates.io maintainer account to publish malicious versions of arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 that pulled the typosquatted proc-macro1 build-time dropper. Building an affected Rust project automatically downloaded and executed a cross-platform backdoor, exposing developer workstations and CI runners; crates.io removed the releases, restored maliciously yanked clean versions, and locked the affected account. Wiz found significant infrastructure overlap with DPRK-linked Mastra/Sapphire Sleet and UNC1069 activity.

Related Actors

Related Reports

« Back