Threat reportSupply ChainTL-2026-2083

Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attack

criticalCONTAINED

Popular Rust Packages With 244M Downloads Compromised in (TL-2026-2083), also tracked as Rust/Crates.io Supply Chain Attack 2026, is a critical-severity supply-chain compromise, first published 2026-08-20. It is attributed to UNC1069 (North Korea) with high confidence, affects Rust Foundation crates.io ecosystem (arrayref), maps to 24 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 31 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
2UNC1069
Detection rules
9SPL · KQL · Sigma
IOCs
31Indicators of compromise

Key facts for TL-2026-2083

Threat ID
TL-2026-2083
Also known as
Rust/Crates.io Supply Chain Attack 2026, BurntSushi Crates.io Compromise
Severity
CRITICAL
Status
CONTAINED
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
UNC1069, APT38
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
software-development, technology, cryptocurrency, open-source
Target regions
Global
Detection rules
9
Indicators of compromise
31

Malware and tooling in Popular Rust Packages With 244M Downloads Compromised in

Malware and tooling: aovine, arone, aronenao, proc-macro-en, proc-macro1, proc-macro1 infostealer, systemd, tinymember, AES-128-GCM encrypted C2 with RSA-2048 command auth

How Popular Rust Packages With 244M Downloads Compromised in works

On August 20, 2026, the crates.io account of Andrew Gallant (BurntSushi, creator of ripgrep) was compromised via stolen credentials, leading to hijacked versions of arrayref (244M downloads), append-only-vec, and internment. These packages were silently modified to depend on a typosquat crate (proc-macro1) whose build.rs downloaded and executed a DPRK-linked backdoor — an infostealer that harvested Chromium browser credentials, cryptocurrency wallet data, and established C2 persistence via LaunchAgent (macOS), systemd (Linux), and Registry Run keys (Windows). The attack was attributed by Wiz Research to UNC1069/Sapphire Sleet (North Korea) based on shared C2 endpoints, SSL certificates, and hosting infrastructure. Malicious versions were online for 86–107 minutes before the Rust Security Response Team deleted them.

On 2026-08-20, a sophisticated supply chain attack targeted the Rust crates.io ecosystem through account compromise of Andrew Gallant (crates.io user droundy), the widely-respected maintainer of the ripgrep tool and multiple popular crates. The attacker, operating from the crates.io typosquat account dtolney (impersonating David Tolnay, dtolnay), first published the typosquat crate proc-macro1 — a deliberate misspelling of the legitimate proc-macro2 crate (154M+ downloads). The malicious crate copied the legitimate crate's description, documentation, and author metadata (forged as rchaitm@gmail.com) to appear trustworthy, while its build.rs contained the entire payload delivery mechanism.

The attack chain unfolded across approximately 107 minutes. At 07:10 UTC, proc-macro1@1.0.107 was published. Within minutes, the compromised droundy account published arrayref@0.3.10 (07:15 UTC), internment@0.8.7 (07:34 UTC), and append-only-vec@0.1.9 (07:37 UTC) — each with a single injected line in Cargo.toml declaring proc-macro1 as a dependency. Because arrayref had never added a dependency in its ten-year history, this sudden change was a red flag that tipped off researchers. The library source code of the legitimate crates remained untouched, meaning manual code review would not have caught the compromise.

The proc-macro1 build.rs executed automatically whenever Cargo compiled any project depending on the tainted versions. It reconstructed two C2 URLs from base64-encoded fragments (aHR0cHM6Ly8=, MjMuMjU0Lg==, MTY1Lg==, MTEyOg==, OTA4OS8=, etc.) to evade static string-based detection. The decoded URLs pointed to a Hostwinds VPS at 23.254.165.112:9089 for payload delivery and 23.254.165.112:443 for C2 beaconing. TLS certificate validation was disabled via a custom AcceptAll verifier.

Based on the victim's operating system and architecture (Linux x86_64, Windows x86_64, macOS x86_64, macOS aarch64), the script downloaded a matching stage-2 payload (rust-crate_0.1.0 through 0.4.0). On Unix systems, the payload was written to /tmp/rust-setup, made executable, and spawned as a detached background process with std::mem::forget(child) to escape Cargo's job object. On Windows, a PowerShell script was launched via a VBS wrapper under wscript.exe, also designed to escape the build process's lifetime.

The stage-2 payload was a full-featured Rust backdoor communicating via HTTPS POST to the endpoint /49890878. It exfiltrated host information and stolen credentials as base64-encoded JSON on a configurable beacon interval. Credential theft targeted Chromium-based browsers (Chrome, Brave, Edge) by querying their SQLite login databases — extracting origin URLs, usernames, and password values. It also accessed Local Extension Settings storage, which is commonly used by browser-based cryptocurrency wallet extensions to store seed phrases and private keys.

Persistence mechanisms were platform-specific: a LaunchAgent plist written to ~/Library/LaunchAgents with RunAtLoad on macOS; a systemd user service dropping MonoService and MonoXpc executables to $HOME/.config/AzureKits and $HOME/.config/ServiceKit on Linux; and a Registry Run key on Windows. Configuration was protected with AES-128-GCM (hardcoded key: 'i am botking'), and C2 commands were authenticated via an embedded RSA-2048 private key. The implant supported four commands: kill (terminate), minicfg (reconfigure C2 and beacon interval), startup (install persistence), and runscript (download and execute arbitrary shell/PowerShell scripts). If the primary C2 became unreachable, a DGA fallback generated 10 algorithmic .com domains every 5 days (none were registered at time of analysis).

The attack was detected by Aikido Security's automated pipeline, which flagged proc-macro1 as a new package downloading and executing remote files. Aikido escalated within the same hour when two trusted packages from the same maintainer suddenly added proc-macro1 as a dependency. Nextron Systems independently discovered the incident and reported it to the Rust Security Response Team. The response team deleted all malicious versions within 86-107 minutes of publication (arrayref at 08:41 UTC, internment at 09:04 UTC, append-only-vec at 09:25 UTC), locked the compromised droundy account, and un-yanked legitimate versions that the attacker had maliciously yanked. Six attacker-controlled crates were entirely deleted: proc-macro1, proc-macro-en, aovine, arone, aronenao, and tinymember.

Wiz Research analyzed recovered payloads and found significant overlap with North Korean state-sponsored campaigns tracked as UNC1069 (Google), Sapphire Sleet (Microsoft), BlueNoroff, and STARDUST CHOLLIMA. Evidence included: (1) the identical C2 endpoint /49890878 was previously used in the Mastra npm supply chain compromise (June 2026), attributed by Microsoft to DPRK/Sapphire Sleet; (2) the SSL certificate issuer WIN-A6QF8AHPQH1\Administrator@WIN-A6QF8AHPQH1 matched IP 23.254.167.13 in the same Mastra campaign; (3) victim-reported C2 traffic to 23.254.167.216 appeared in Google Cloud Threat Intelligence's analysis of UNC1069's axios npm compromise (March 2026), which Mandiant links to North Korea; (4) all campaigns preferred the 23.254.164.0/23 Hostwinds range. The broader campaign known as 'Contagious Interview' has produced over 1,700 malicious packages across npm, PyPI, Go Modules, crates.io, and Packagist since January 2025, using a factory model where identical loader patterns are ported across ecosystems with shared infrastructure.

This was the largest Rust crate compromise by download count. arrayref appears in over 35% of all environments and roughly 75% of Rust-present environments. Because build scripts execute at compile time with full user privileges, simply building a project that depended on these crates was sufficient for infection — no runtime function call was required. The attacker also yanked legitimate recent versions to force users toward the malicious ones, necessitating reverse-yanking by the security team.

MITRE ATT&CK techniques used in TL-2026-2083

Collection

T1005 Data from Local System; T1074.001 Data Staged: Local Data Staging

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hide Artifacts: Hidden Files and Directories

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.004 Command and Scripting Interpreter: Unix Shell; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1573.001 Encrypted Channel: Symmetric Cryptography

Initial Access

T1195 Supply Chain Compromise; T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools

Persistence

T1543.001 Create or Modify System Process: Launch Agent; T1543.002 Create or Modify System Process: Systemd Service; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Credential Access

T1555.003 Credentials from Web Browsers

Resource Development

T1583.003 Acquire Infrastructure: Virtual Private Server; T1585 Establish Accounts; T1586.002 Compromise Accounts: Email Accounts; T1587.001 Develop Capabilities: Malware; T1608.001 Stage Capabilities: Upload Malware

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Popular Rust Packages With 244M Downloads Compromised in

  • Rust Foundation — crates.io ecosystem (arrayref)
    Vulnerable versions: 0.3.10
    Fixed in: 0.3.9 (unyanked by security team)
  • Rust Foundation — crates.io ecosystem (append-only-vec)
    Vulnerable versions: 0.1.9
    Fixed in: 0.1.8 (unyanked by security team)
  • Rust Foundation — crates.io ecosystem (internment)
    Vulnerable versions: 0.8.7
    Fixed in: 0.8.6 (unyanked by security team)
  • Rust Foundation — crates.io ecosystem (proc-macro1 typosquat)
    Vulnerable versions: 1.0.106; 1.0.107
    Fixed in: Deleted from registry
  • Google — Chrome browser
    Vulnerable versions: All versions (targeted for credential theft)
  • Microsoft — Edge browser
    Vulnerable versions: All versions (targeted for credential theft)
  • Brave Software — Brave browser
    Vulnerable versions: All versions (targeted for credential theft)

Remediation for Popular Rust Packages With 244M Downloads Compromised in

Patches

  • Pin arrayref below version 0.3.10
  • Pin append-only-vec below version 0.1.9
  • Pin internment below version 0.8.7
  • Rebuild all artifacts from clean sources after credential rotation

Immediate actions

  • Search Cargo.lock and ~/.cargo/registry/cache/ for tainted versions: arrayref@0.3.10, append-only-vec@0.1.9, internment@0.8.7, and any version of proc-macro1, proc-macro-en, aovine, arone, aronenao, tinymember
  • Treat any host that built these versions during the 86-107 minute window as fully compromised
  • Rotate ALL credentials, tokens, CI secrets, and signing keys stored on affected systems
  • Rotate browser-stored credentials from Chrome, Brave, and Edge on affected systems
  • Search for payload artifacts: /tmp/rust-setup (Unix), %TEMP%\rust-setup.ps1 (Windows), %TEMP%\rust-setup-launch.vbs (Windows)
  • Check for unrecognized systemd user services, Registry Run keys, and LaunchAgents

Workarounds

  • Audit CI/CD pipelines that ran cargo build during the 07:10-09:25 UTC window on 2026-08-20
  • Use cargo vet or cargo crev for supply chain integrity verification before dependency updates

Longer-term hardening

  • Implement dependency pinning and hash-locked lockfiles across all Rust projects
  • Enforce 2FA on ALL crates.io publishing accounts with hardware security keys
  • Deploy CI/CD pipeline scanning for unexpected new build-dependencies, especially crates performing network calls in build.rs
  • Monitor build logs for anomalous outbound connections during compilation
  • Treat sudden yanking of multiple stable versions of a long-lived crate as a warning signal

Weaknesses (CWE) in Popular Rust Packages With 244M Downloads Compromised in

CWE-494, CWE-506, CWE-522, CWE-829, CWE-1104

Timeline of Popular Rust Packages With 244M Downloads Compromised in

  • DPRK threat actors begin systematic open-source supply chain campaign (Contagious Interview) — over 1,700 malicious packages published across npm, PyPI, Go Modules, crates.io, and Packagist by April 2026
  • UNC1069/Sapphire Sleet compromises the maintainer account of the axios npm package (~100M weekly downloads), linking the same Hostwinds infrastructure (23.254.167.216) as later seen in the arrayref attack
  • Mastra npm supply chain compromise: 140+ @mastra/* packages poisoned via typosquat easy-day-js with postinstall dropper, attributed to DPRK/Sapphire Sleet. Uses same C2 pattern (/49890878) and Hostwinds infrastructure (23.254.164.92:8000)
  • Aikido Security publishes detailed technical analysis with build.rs code breakdown, stage-2 payload analysis, credential theft mechanics, and full IOC list
  • Rust Foundation publishes official security advisory detailing the attack, crediting Nextron Systems for discovery and naming the Rust Security Response Team participants
  • Wiz Research publishes analysis finding significant overlap with DPRK campaigns: shared C2 endpoint /49890878 (Mastra campaign), shared SSL issuer (WIN-A6QF8AHPQH1), shared Hostwinds 23.254.164.0/23 infrastructure, and infrastructure overlap with UNC1069's axios attack
  • 09:25 UTC — append-only-vec@0.1.9 deleted from crates.io (107 minutes online). All six attacker-controlled crates (proc-macro1, proc-macro-en, aovine, arone, aronenao, tinymember) also deleted. droundy account locked as precautionary measure
  • 09:04 UTC — internment@0.8.7 deleted from crates.io (90 minutes online)
  • 08:41 UTC — arrayref@0.3.10 deleted from crates.io (86 minutes online). The attacker had yanked legitimate older versions; security team reverse-yanks them
  • 07:37 UTC — Compromised account publishes append-only-vec@0.1.9 with proc-macro1 dependency (~4.5M downloads)
  • 07:34 UTC — Compromised account publishes internment@0.8.7 with proc-macro1 dependency
  • 07:25 UTC — Aikido Security pipeline flags proc-macro1 as a suspicious new package downloading and executing remote files
  • 07:15 UTC — Compromised droundy account publishes arrayref@0.3.10 with proc-macro1 as a dependency (244M lifetime downloads, its first dependency in 10 years). Rust Security Response Team receives initial report from Nextron Systems within minutes
  • 07:10 UTC — Attacker-controlled crates.io account dtolney publishes proc-macro1@1.0.107 (typosquat of proc-macro2) containing malicious build.rs with base64-obfuscated C2 URLs

Sources cited for Popular Rust Packages With 244M Downloads Compromised in

Detection coverage for TL-2026-2083

As of 2026-08-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2083 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
31 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2083

8 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats