Threat reportSupply ChainTL-2026-2085
Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via proc-macro1 Typosquat (DPRK/Sapphire Sleet)
Popular Rust Crates arrayref, internment, append-only-vec (TL-2026-2085), also tracked as Operation Rusty Crate, is a critical-severity supply-chain compromise, first published 2026-08-20 and last reviewed 2026-08-21. It is attributed to APT38 (North Korea) with high confidence, affects Rust (crates.io) arrayref, maps to 29 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 35 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 29MITRE ATT&CK
- Actors
- 2APT38
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 35Indicators of compromise
Key facts for TL-2026-2085
- Threat ID
- TL-2026-2085
- Also known as
- Operation Rusty Crate, proc-macro1 Supply Chain Campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- APT38, UNC1069
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Target sectors
- software-development, technology, open-source, devops, cloud
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 35
- Updates
- 2026-08-21 · revalidated 1× · latest source
How Popular Rust Crates arrayref, internment, append-only-vec works
On August 20, 2026, three legitimate Rust crates (arrayref, internment, append-only-vec) maintained by David Roundy (droundy) were compromised via a typosquat dependency proc-macro1 impersonating proc-macro2. During Cargo builds, proc-macro1's build.rs downloads and executes a cross-platform stage-2 backdoor capable of browser credential theft, persistence (systemd/LaunchAgent/Run key), and HTTPS C2 beaconing. The Rust Security Response Team confirmed the maintainer's account was compromised and remediated within ~2 hours. Wiz Research attributes the attack to North Korean state-sponsored group Sapphire Sleet (UNC1069) based on C2 infrastructure overlap with the Mastra npm campaign. arrayref has ~152M+ clean downloads; the malicious versions were online for 86-107 minutes.
On August 20, 2026, a coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy (crates.io user droundy): arrayref (a widely used macro for safe array referencing, ~152M+ downloads), internment (an interning library), and append-only-vec (an append-only vector). The attacker gained access to the maintainer's crates.io account through compromised credentials, then published malicious versions (arrayref@0.3.10, internment@0.8.7, append-only-vec@0.1.9) that each added a single typosquat dependency: proc-macro1, impersonating the legitimate and widely used proc-macro2 crate (154M+ downloads). The attacker also yanked legitimate versions of arrayref (0.3.5-0.3.9) to steer dependency resolution toward the malicious release.
The typosquat proc-macro1 crate was published by a forged identity (dtolney, with the email rchaitm@gmail.com) and replicated the genuine proc-macro2 source code as camouflage. Its Cargo.toml metadata forged the author as David Tolnay and linked to a non-existent GitHub repository. The malicious logic resided entirely in build.rs, which executes automatically during cargo build — no import or explicit function call by the application is needed. The build.rs reconstructs C2 addresses from Base64-encoded fragments, disables TLS certificate validation via a custom AcceptAll ServerCertVerifier, detects the victim's OS and architecture, and downloads a platform-specific stage-2 payload from 23.254.165.112:9089. On Unix systems it writes /tmp/rust-setup, sets executable permissions, and spawns it detached. On Windows it writes %TEMP%\rust-setup.ps1 plus a VBS launcher and executes via wscript.exe with hidden PowerShell ExecutionPolicy Bypass and CREATE_NO_WINDOW, using std::mem::forget to escape Cargo's job object.
The stage-2 backdoor (analyzed across four platform-specific variants — Linux x86-64, Windows x86-64, macOS x86-64, macOS ARM64) shares a common protocol, configuration structure, AES-128-GCM encryption (hardcoded key 'i am botking'), and RSA-2048 command authentication. It performs host profiling (username, hostname, OS, architecture, privilege level, installed applications), inventories Chromium-based browsers (Chrome, Brave, Edge) for visited login origins and extension identifiers, and establishes C2 beaconing via HTTPS POST to /49890878. The backdoor supports four commands: kill, minicfg (reconfigure C2/beacon interval), startup (install persistence), and runscript (download and execute arbitrary scripts). Persistence mechanisms are OS-specific: Windows HKCU Run key, Linux systemd user service, macOS LaunchAgent. When primary C2 is unreachable, the implant falls back to a Domain Generation Algorithm producing ten deterministic .com domains rotated every 5 days.
Wiz Research attributes the attack to North Korean state-sponsored group Sapphire Sleet (also tracked as UNC1069 by Google/Mandiant and BlueNoroff) based on multiple infrastructure overlaps: the C2 endpoint /49890878 was previously used in the Mastra npm supply chain campaign (attributed by Microsoft to DPRK/Sapphire Sleet); the SSL certificate issuer WIN-A6QF8AHPQH1\Administrator matches infrastructure from the Mastra operation; C2 traffic to 23.254.167.216 appears in Google Cloud Threat Intelligence's analysis of UNC1069's axios npm attack (April 2026); and the entire operation uses the 23.254.164.0/23 Hostwinds LLC IP range consistent with DPRK-linked activity. This campaign is part of a broader DPRK effort (Contagious Interview) that has targeted five ecosystems — npm, PyPI, Go Modules, crates.io, and Packagist — with 1,700+ malicious packages since January 2025.
Socket.dev's AI Scanner independently detected proc-macro1 as malicious at 07:29:50 UTC on the day of the attack. Nextron Systems separately reported the activity to the Rust Security Response Team, which deleted all malicious versions within approximately two hours (86-107 minutes online per affected crate), locked the compromised droundy account, and restored the yanked legitimate versions. Users are advised to pin affected crates to clean versions, scan Cargo.lock for malicious dependencies, check ~/.cargo/registry/cache for attacker crate artifacts, and treat any system that built a malicious version as potentially compromised — rotating all credentials and secrets accessible to affected build environments.
MITRE ATT&CK techniques used in TL-2026-2085
Collection
T1005 Data from Local System; T1119 Automated Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1553 Subvert Trust Controls
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.004 Command and Scripting Interpreter: Unix Shell; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1573.001 Encrypted Channel: Symmetric Cryptography; T1573.002 Encrypted Channel: Asymmetric Cryptography
Initial Access
T1078 Valid Accounts; T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery
Persistence
T1543.001 Create or Modify System Process: Launch Agent; T1543.002 Create or Modify System Process: Systemd Service; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Credential Access
T1555.003 Credentials from Web Browsers
Resource Development
T1583 Acquire Infrastructure; T1583.003 Acquire Infrastructure: Virtual Private Server; T1587.001 Develop Capabilities: Malware; T1588 Obtain Capabilities; T1608.001 Stage Capabilities: Upload Malware
Reconnaissance
Affected products and versions in Popular Rust Crates arrayref, internment, append-only-vec
- Rust (crates.io) — arrayref
Vulnerable versions: 0.3.10
Fixed in: 0.3.9 and prior - Rust (crates.io) — internment
Vulnerable versions: 0.8.7
Fixed in: 0.8.6 and prior - Rust (crates.io) — append-only-vec
Vulnerable versions: 0.1.9
Fixed in: 0.1.8 and prior - Rust (crates.io) — proc-macro1 (typosquat)
Vulnerable versions: all versions
Fixed in: deleted from registry - Rust (crates.io) — proc-macro-en (attacker-controlled)
Vulnerable versions: all versions
Fixed in: deleted from registry - Hostwinds LLC — VPS infrastructure (23.254.164.0/23)
Vulnerable versions: C2 servers at 23.254.165.112, 23.254.167.107, 23.254.167.216
Remediation for Popular Rust Crates arrayref, internment, append-only-vec
Patches
- Pin arrayref to <= 0.3.9 (clean version)
- Pin internment to <= 0.8.6 (clean version)
- Pin append-only-vec to <= 0.1.8 (clean version)
- Add explicit proc-macro2 dependency pinned to known-good version if not already present
Immediate actions
- Check Cargo.lock for malicious crate versions (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9) and six attacker-controlled crate names (proc-macro1, proc-macro-en, aovine, arone, aronenao, tinymember)
- Search ~/.cargo/registry/cache for attacker crate files using SHA-256 hashes
- Block 23.254.164.0/23 IP range at perimeter firewalls and on developer endpoints
- Add Suricata/Snort rules to detect beaconing to /49890878 endpoint
- Treat any system that built a malicious version as fully compromised — disconnect from network and initiate incident response
Workarounds
- Audit all Cargo.lock files before any build in CI/CD pipelines
- Run cargo audit or cargo deny in CI with dependency allowlists
- Use RustSec advisory-db integration to detect known-vulnerability dependencies
- Consider implementing build-time network monitoring for unexpected outbound connections from build.rs scripts
Longer-term hardening
- Deploy software composition analysis (SCA) tooling with automated dependency scanning
- Implement dependency pinning for all production crates
- Use vendored/in-tree dependencies for critical crates
- Enforce code review on all Cargo.toml dependency additions
- Deploy runtime detection for unexpected build.rs network connections during cargo builds
Weaknesses (CWE) in Popular Rust Crates arrayref, internment, append-only-vec
Timeline of Popular Rust Crates arrayref, internment, append-only-vec
Showing the 20 most recent tracked events.
- RustSec publishes RUSTSEC-2026-0260, categorizing arrayref 0.3.10 as malicious with no patched version and no confirmed evidence of in-the-wild usage.
- 09:09 UTC — blake3 1.8.7 ships without the arrayref dependency, removing transitive exposure for blake3's downstream users.
- 08:03 UTC — Cleanup begins: proc-macro1 deleted from the crates.io index.
- 07:54 UTC — Incident reported to the Rust Security Response Team by GitHub user jhobern; RustSec advisory-db issue filed.
- Within 24 seconds of publishing arrayref 0.3.10, the attacker script-yanked versions 0.3.5-0.3.9, leaving 0.3.10 as the only installable release.
- 07:11 UTC — proc-macro1 1.0.107 published, adding base64, rustls, and ureq as build-dependencies to form a complete downloader toolkit inside build.rs.
- 01:17-01:25 UTC — GitHub account 'dtolney' and matching crates.io impersonation account (user ID 438608) created, one transposed letter from legitimate author dtolnay; forged author metadata uses email rchaitm@gmail.com.
- Wiz Research publishes attribution analysis linking the attack to North Korean state-sponsored group Sapphire Sleet (UNC1069) based on C2 endpoint, SSL certificate, and IP range overlap with the Mastra npm supply chain campaign
- Rust Security Response Team deletes all six attacker-controlled crates (proc-macro1, proc-macro-en, aovine, arone, aronenao, tinymember), locks compromised droundy account, and restores yanked legitimate versions
- append-only-vec@0.1.9 deleted from crates.io at 09:25:24 UTC (107 minutes online)
- internment@0.8.7 deleted from crates.io at 09:04:11 UTC (90 minutes online)
- arrayref@0.3.10 deleted from crates.io at 08:41:40 UTC (86 minutes online)
- Rust Security Response Team receives initial report at 07:15 UTC and begins verification and response
- append-only-vec@0.1.9 malicious version published at 07:37:49 UTC
- internment@0.8.7 malicious version published at 07:34:07 UTC
- Socket.dev AI Scanner independently detects proc-macro1 as malicious at 07:29:50 UTC; Nextron Systems separately identifies and reports the attack to the Rust Security Response Team
- arrayref@0.3.10 published to crates.io at 07:15:00 UTC with injected dependency on typosquat proc-macro1@1.0.107
- Attacker yanks legitimate arrayref versions 0.3.5 through 0.3.9 to steer dependency resolution toward the upcoming malicious release
- Attacker compromises maintainer droundy's crates.io credentials, gains administrative access to arrayref, internment, and append-only-vec
- Attacker publishes proc-macro1@1.0.106 (clean staging copy of proc-macro2) to crates.io under forged identity dtolney
Update history for TL-2026-2085
- 2026-08-21 — Rust crates.io Supply Chain Attack — Compromised arrayref, internment, append-only-vec via typosquatting build-script payload: What changed No severity/exploitability/status escalation — both reports already rate this CRITICAL/ACTIVE. The newer report adds attack-chain precision: pre-staging two days in advance (arone/aronenao), the dtolney impersonation account cr
Sources cited for Popular Rust Crates arrayref, internment, append-only-vec
- Rust Security Response Team: Supply Chain Attack on arrayref
- Socket.dev: Popular Rust Crates Compromised in Build-Time Supply Chain Attack
- Wiz Research: Rust Supply Chain Attack on arrayref — Significant Overlap with DPRK Campaigns
- RustSec Advisory DB — Issue 3161: arrayref supply chain attack via proc-macro1
- Aikido.dev: Compromised Rust Crate onering Performs Code Exfiltration (related incident)
- Microsoft: DPRK Sapphire Sleet Mastra npm supply chain attack
- Mandiant: UNC1069 multi-ecosystem supply chain campaigns
- CISA Known Exploited Vulnerabilities Catalog
Detection coverage for TL-2026-2085
As of 2026-08-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2085 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2085
8 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.