Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Climate Change Reshuffles Where People Are Moving in Florida

    August 20, 2026

    U.S.-Canada Trade Talks Aim to Avert Another Tariff War

    August 20, 2026

    Kyiv’s Dormition Cathedral is Revived After Russian Drone Strike

    August 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Climate Change Reshuffles Where People Are Moving in Florida
    • U.S.-Canada Trade Talks Aim to Avert Another Tariff War
    • Kyiv’s Dormition Cathedral is Revived After Russian Drone Strike
    • Paris St-Germain move game after heat damages Parc des Princes pitch
    • Reform’s new economic adviser has called for end of pensioners’ triple lock | Reform UK
    • Leaders attack ‘demotivating’ plan to make pupils who fail GCSEs retake maths and English | Education
    • The US Treasury is buying long bonds, but not very many
    • Someone targeted security researchers using a fake crypto conference as a lure
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 20
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers poison arrayref Rust crate to push infostealer malware

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 20, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers’ systems during compilation.

    Within a 23-minute window, the attacker also poisoned two other crates, append-only-vec and internment, in the same supply-chain attack.

    The arrayref crate is a popular Rust library with more than 53 million downloads over the past 90 days that is used by cryptography, graphics, and blockchain tools.

    image

    A report from application security company StepSecurity notes that the malicious Rust crate releases were arrayref 0.3.10, append-only-vec 0.1.9, and internment 0.8.7, all maintained by the same account.

    The hacker injected a dependency on a package called proc-macro1, a typosquat impersonating the popular proc-macro2 crate, while retaining the rest of the upstream source code completely unchanged.

    According to the researchers, a script in proc-macro1, named ‘build.rs,’ is automatically executed during compilation, reconstructing its infrastructure from base64-encoded fragments and selecting a payload that matches the host OS (Linux x86-64, Windows x86-64, macOS x86-64, and macOS ARM64).

    StepSecurity says that the attacker also published multiple versions of four crates themselves (aovine, arone, aronenao, tinymember), which have been removed from crates.io.

    On Unix systems, the malware writes to /tmp/rust-setup, marks it executable, and launches it as a detached process.

    On Windows, it creates %TEMP%rust-setup.ps1 and uses a hidden wscript.exe and VBS launcher to keep the process running.

    The payload receives an address as an argument, believed to be a command-and-control address.

    According to an analysis from cloud security company Wiz, the second-stage capabilities include exfiltrating host info and credentials.

    The researchers say that the malware collects credentials from Google Chrome, Brave, and Edge browsers by querying SQLite login databases.

    Persistence is established via the Registry Run key on Windows, LaunchAgent on macOS, and systemd on Linux.

    Timeline and impact

    The potential impact of this supply-chain attack is significant, as arrayref alone has more than 245 million lifetime downloads, while the collective count for append-only-vec and internment is nearly 19 million installs.

    Projects using arrayref include blake3, Rust GUI frameworks such as egui, eframe, and iced, and components used in Ethereum and Solana.

    The attack started at 01:17 UTC on August 20, when a GitHub account impersonating prominent Rust developer David Tolnay was created, followed by a similar account in the crates.io registry.

    At 01:55, the attacker published proc-macro1@1.0.106, a benign copy of proc-macro2, followed by a malicious update through version 1.0.107, published at 7:11.

    At 07:15, arrayref 0.3.10 was published through the legitimate droundy (David Roundy) account, while versions 0.3.5 through 0.3.9 were removed, potentially to force installation of the malicious release.

    The incident was reported at 07:54. Crates.io deleted proc-macro1 at 08:03 and removed arrayref 0.3.10 from the index at 08:41.

    Cybersecurity companies StepSecurity, SafeDep, and Aikido have each published a technical analysis of the supply-chain attack and shared indicators of compromise.

    Wiz researchers note that “the campaign’s infrastructure overlaps with recent DPRK [North Korean] supply chain attacks, including Mastra and axios.”

    Developers who installed either during the exposure window of nearly 1.5 hours should assume compromise.

    Recommended checks include searching Cargo.lock files, looking for the dropped files, and reviewing traffic to 23.254.165[.]112 on ports 9089 and 443.

    Where compromise is confirmed, it is recommended to rotate all accessible credentials, CI tokens, signing keys, and other secrets, and rebuild the environment from safe backups.

    Clean projects should pin a known-safe version of the affected dependencies until the maintainer situation is clarified and resolved.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    arrayref crate hackers infostealer Malware Poison Push Rust
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Citrix issues critical security updates for its NetScaler devices

    Kriminal breaks out of Grok, Claude guardrails at $12.99

    New Manic Android malware can exfiltrate data through nearby devices

    How MSPs can catch phishing attacks email filters miss

    Critical Elementor Pro bug exposes WordPress sites to RCE attacks

    Agentic AI Presents New Insider Threat Model for Orgs

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Climate Change Reshuffles Where People Are Moving in Florida

    August 20, 2026

    U.S.-Canada Trade Talks Aim to Avert Another Tariff War

    August 20, 2026

    Kyiv’s Dormition Cathedral is Revived After Russian Drone Strike

    August 20, 2026

    Paris St-Germain move game after heat damages Parc des Princes pitch

    August 20, 2026
    Latest Posts

    New Dysphoria DDoS botnet spreads to 200k devices worldwide

    July 28, 2026

    OpenAI’s biggest threat may just be open AI

    July 28, 2026

    6 Takeaways From Michigan’s Senate Debate Between Abdul El-Sayed and Haley Stevens

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Climate Change Reshuffles Where People Are Moving in Florida

    August 20, 2026

    U.S.-Canada Trade Talks Aim to Avert Another Tariff War

    August 20, 2026

    Kyiv’s Dormition Cathedral is Revived After Russian Drone Strike

    August 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.