# Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attack

> On August 20, 2026, the crates.io account of Andrew Gallant (BurntSushi, creator of ripgrep) was compromised via stolen credentials, leading to hijacked versions of arrayref (244M downloads), append-only-vec, and internment. These packages were silently modified to depend on a typosquat crate (proc-macro1) whose build.rs downloaded and executed a DPRK-linked backdoor — an infostealer that harvested Chromium browser credentials, cryptocurrency wallet data, and established C2 persistence via LaunchAgent (macOS), systemd (Linux), and Registry Run keys (Windows). The attack was attributed by Wiz Research to UNC1069/Sapphire Sleet (North Korea) based on shared C2 endpoints, SSL certificates, and hosting infrastructure. Malicious versions were online for 86–107 minutes before the Rust Security Response Team deleted them.

- **Published:** 2026-08-20T00:00:00Z
- **Last reviewed:** 2026-08-20T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2083
- **ID:** TL-2026-2083
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** CONTAINED
- **Actor:** UNC1069 (North Korea)
- **Detections:** 9 · **IOCs:** 31 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-08-20, a sophisticated supply chain attack targeted the Rust crates.io ecosystem through account compromise of Andrew Gallant (crates.io user droundy), the widely-respected maintainer of the ripgrep tool and multiple popular crates. The attacker, operating from the crates.io typosquat account dtolney (impersonating David Tolnay, dtolnay), first published the typosquat crate proc-macro1 — a deliberate misspelling of the legitimate proc-macro2 crate (154M+ downloads). The malicious crate copied the legitimate crate's description, documentation, and author metadata (forged as rchaitm@gmail.com) to appear trustworthy, while its build.rs contained the entire payload delivery mechanism.

The attack chain unfolded across approximately 107 minutes. At 07:10 UTC, proc-macro1@1.0.107 was published. Within minutes, the compromised droundy account published arrayref@0.3.10 (07:15 UTC), internment@0.8.7 (07:34 UTC), and append-only-vec@0.1.9 (07:37 UTC) — each with a single injected line in Cargo.toml declaring proc-macro1 as a dependency. Because arrayref had never added a dependency in its ten-year history, this sudden change was a red flag that tipped off researchers. The library source code of the legitimate crates remained untouched, meaning manual code review would not have caught the compromise.

The proc-macro1 build.rs executed automatically whenever Cargo compiled any project depending on the tainted versions. It reconstructed two C2 URLs from base64-encoded fragments (aHR0cHM6Ly8=, MjMuMjU0Lg==, MTY1Lg==, MTEyOg==, OTA4OS8=, etc.) to evade static string-based detection. The decoded URLs pointed to a Hostwinds VPS at 23.254.165.112:9089 for payload delivery and 23.254.165.112:443 for C2 beaconing. TLS certificate validation was disabled via a custom AcceptAll verifier.

Based on the victim's operating system and architecture (Linux x86_64, Windows x86_64, macOS x86_64, macOS aarch64), the script downloaded a matching stage-2 payload (rust-crate_0.1.0 through 0.4.0). On Unix systems, the payload was written to /tmp/rust-setup, made executable, and spawned as a detached background process with std::mem::forget(child) to escape Cargo's job object. On Windows, a PowerShell script was launched via a VBS wrapper under wscript.exe, also designed to escape the build process's lifetime.

The stage-2 payload was a full-featured Rust backdoor communicating via HTTPS POST to the endpoint /49890878. It exfiltrated host information and stolen credentials as base64-encoded JSON on a configurable beacon interval. Credential theft targeted Chromium-based browsers (Chrome, Brave, Edge) by querying their SQLite login databases — extracting origin URLs, usernames, and password values. It also accessed Local Extension Settings storage, which is commonly used by browser-based cryptocurrency wallet extensions to store seed phrases and private keys.

Persistence mechanisms were platform-specific: a LaunchAgent plist written to ~/Library/LaunchAgents with RunAtLoad on macOS; a systemd user service dropping MonoService and MonoXpc executables to $HOME/.config/AzureKits and $HOME/.config/ServiceKit on Linux; and a Registry Run key on Windows. Configuration was protected with AES-128-GCM (hardcoded key: 'i am botking'), and C2 commands were authenticated via an embedded RSA-2048 private key. The implant supported four commands: kill (terminate), minicfg (reconfigure C2 and beacon interval), startup (install persistence), and runscript (download and execute arbitrary shell/PowerShell scripts). If the primary C2 became unreachable, a DGA fallback generated 10 algorithmic .com domains every 5 days (none were registered at time of analysis).

The attack was detected by Aikido Security's automated pipeline, which flagged proc-macro1 as a new package downloading and executing remote files. Aikido escalated within the same hour when two trusted packages from the same maintainer suddenly added proc-macro1 as a dependency. Nextron Systems independently discovered the incident and reported it to the Rust Security Response Team. The response team deleted all malicious versions within 86-107 minutes of publication (arrayref at 08:41 UTC, internment at 09:04 UTC, append-only-vec at 09:25 UTC), locked the compromised droundy account, and un-yanked legitimate versions that the attacker had maliciously yanked. Six attacker-controlled crates were entirely deleted: proc-macro1, proc-macro-en, aovine, arone, aronenao, and tinymember.

Wiz Research analyzed recovered payloads and found significant overlap with North Korean state-sponsored campaigns tracked as UNC1069 (Google), Sapphire Sleet (Microsoft), BlueNoroff, and STARDUST CHOLLIMA. Evidence included: (1) the identical C2 endpoint /49890878 was previously used in the Mastra npm supply chain compromise (June 2026), attributed by Microsoft to DPRK/Sapphire Sleet; (2) the SSL certificate issuer WIN-A6QF8AHPQH1\Administrator@WIN-A6QF8AHPQH1 matched IP 23.254.167.13 in the same Mastra campaign; (3) victim-reported C2 traffic to 23.254.167.216 appeared in Google Cloud Threat Intelligence's analysis of UNC1069's axios npm compromise (March 2026), which Mandiant links to North Korea; (4) all campaigns preferred the 23.254.164.0/23 Hostwinds range. The broader campaign known as 'Contagious Interview' has produced over 1,700 malicious packages across npm, PyPI, Go Modules, crates.io, and Packagist since January 2025, using a factory model where identical loader patterns are ported across ecosystems with shared infrastructure.

This was the largest Rust crate compromise by download count. arrayref appears in over 35% of all environments and roughly 75% of Rust-present environments. Because build scripts execute at compile time with full user privileges, simply building a project that depended on these crates was sufficient for infection — no runtime function call was required. The attacker also yanked legitimate recent versions to force users toward the malicious ones, necessitating reverse-yanking by the security team.

## MITRE ATT&CK

- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1586.002 Compromise Accounts: Email Accounts
- T1587.001 Develop Capabilities: Malware
- T1608.001 Stage Capabilities: Upload Malware
- T1585 Establish Accounts
- T1195 Supply Chain Compromise
- T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools
- T1204.002 User Execution: Malicious File
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1543.001 Create or Modify System Process: Launch Agent
- T1543.002 Create or Modify System Process: Systemd Service
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1036 Masquerading
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1564.001 Hide Artifacts: Hidden Files and Directories
- T1140 Deobfuscate/Decode Files or Information
- T1555.003 Credentials from Web Browsers
- T1005 Data from Local System
- T1074.001 Data Staged: Local Data Staging
- T1071.001 Application Layer Protocol: Web Protocols
- T1573.001 Encrypted Channel: Symmetric Cryptography

## Sources

- [Rust Blog — Supply chain attack on arrayref](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/)
- [Wiz Research — Supply chain attack on arrayref: significant overlap with DPRK campaigns](https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns)
- [Aikido Security — Two Popular Rust Crates Compromised in Supply Chain Attack](https://www.aikido.dev/blog/two-popular-rust-crates-arrayref-and-append-only-vec-compromised-in-supply-chain-attack)
- [Cyber Security News — Popular Rust Packages With 244M Downloads Compromised to Run Malware](https://cybersecuritynews.com/rust-packages-malware/)
- [Microsoft Security — Postinstall payload inside Mastra npm supply chain compromise](https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/)
- [Cloud Security Alliance — DPRK Contagious Interview Cross-Ecosystem Research Note](https://labs.cloudsecurityalliance.org/research/csa-research-note-dprk-contagious-interview-cross-ecosystem/)
- [AWS Security Blog — Amazon Identifies North Korean Hacker Group Behind Open Source Supply Chain Attacks](https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/)
- [BleepingComputer — Microsoft links Mastra AI supply chain attack to North Korean hackers](https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/)
- [Mastra AI GitHub Issue — Incident Report](https://github.com/mastra-ai/mastra/issues/18061)
- [The Hacker News — N. Korean Hackers Spread 1,700 Malicious Packages Across 5 Package Registries](https://thehackernews.com/2026/04/n-korean-hackers-spread-1700-malicious.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2083
