Threat reportSupply ChainTL-2026-2085

Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via proc-macro1 Typosquat (DPRK/Sapphire Sleet)

criticalACTIVE

Popular Rust Crates arrayref, internment, append-only-vec (TL-2026-2085), also tracked as Operation Rusty Crate, is a critical-severity supply-chain compromise, first published 2026-08-20 and last reviewed 2026-08-21. It is attributed to APT38 (North Korea) with high confidence, affects Rust (crates.io) arrayref, maps to 29 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 35 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
29MITRE ATT&CK
Actors
2APT38
Detection rules
9SPL · KQL · Sigma
IOCs
35Indicators of compromise

Key facts for TL-2026-2085

Threat ID
TL-2026-2085
Also known as
Operation Rusty Crate, proc-macro1 Supply Chain Campaign
Severity
CRITICAL
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
APT38, UNC1069
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
software-development, technology, open-source, devops, cloud
Target regions
Global
Detection rules
9
Indicators of compromise
35
Updates
2026-08-21 · revalidated 1× · latest source

How Popular Rust Crates arrayref, internment, append-only-vec works

On August 20, 2026, three legitimate Rust crates (arrayref, internment, append-only-vec) maintained by David Roundy (droundy) were compromised via a typosquat dependency proc-macro1 impersonating proc-macro2. During Cargo builds, proc-macro1's build.rs downloads and executes a cross-platform stage-2 backdoor capable of browser credential theft, persistence (systemd/LaunchAgent/Run key), and HTTPS C2 beaconing. The Rust Security Response Team confirmed the maintainer's account was compromised and remediated within ~2 hours. Wiz Research attributes the attack to North Korean state-sponsored group Sapphire Sleet (UNC1069) based on C2 infrastructure overlap with the Mastra npm campaign. arrayref has ~152M+ clean downloads; the malicious versions were online for 86-107 minutes.

On August 20, 2026, a coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy (crates.io user droundy): arrayref (a widely used macro for safe array referencing, ~152M+ downloads), internment (an interning library), and append-only-vec (an append-only vector). The attacker gained access to the maintainer's crates.io account through compromised credentials, then published malicious versions (arrayref@0.3.10, internment@0.8.7, append-only-vec@0.1.9) that each added a single typosquat dependency: proc-macro1, impersonating the legitimate and widely used proc-macro2 crate (154M+ downloads). The attacker also yanked legitimate versions of arrayref (0.3.5-0.3.9) to steer dependency resolution toward the malicious release.

The typosquat proc-macro1 crate was published by a forged identity (dtolney, with the email rchaitm@gmail.com) and replicated the genuine proc-macro2 source code as camouflage. Its Cargo.toml metadata forged the author as David Tolnay and linked to a non-existent GitHub repository. The malicious logic resided entirely in build.rs, which executes automatically during cargo build — no import or explicit function call by the application is needed. The build.rs reconstructs C2 addresses from Base64-encoded fragments, disables TLS certificate validation via a custom AcceptAll ServerCertVerifier, detects the victim's OS and architecture, and downloads a platform-specific stage-2 payload from 23.254.165.112:9089. On Unix systems it writes /tmp/rust-setup, sets executable permissions, and spawns it detached. On Windows it writes %TEMP%\rust-setup.ps1 plus a VBS launcher and executes via wscript.exe with hidden PowerShell ExecutionPolicy Bypass and CREATE_NO_WINDOW, using std::mem::forget to escape Cargo's job object.

The stage-2 backdoor (analyzed across four platform-specific variants — Linux x86-64, Windows x86-64, macOS x86-64, macOS ARM64) shares a common protocol, configuration structure, AES-128-GCM encryption (hardcoded key 'i am botking'), and RSA-2048 command authentication. It performs host profiling (username, hostname, OS, architecture, privilege level, installed applications), inventories Chromium-based browsers (Chrome, Brave, Edge) for visited login origins and extension identifiers, and establishes C2 beaconing via HTTPS POST to /49890878. The backdoor supports four commands: kill, minicfg (reconfigure C2/beacon interval), startup (install persistence), and runscript (download and execute arbitrary scripts). Persistence mechanisms are OS-specific: Windows HKCU Run key, Linux systemd user service, macOS LaunchAgent. When primary C2 is unreachable, the implant falls back to a Domain Generation Algorithm producing ten deterministic .com domains rotated every 5 days.

Wiz Research attributes the attack to North Korean state-sponsored group Sapphire Sleet (also tracked as UNC1069 by Google/Mandiant and BlueNoroff) based on multiple infrastructure overlaps: the C2 endpoint /49890878 was previously used in the Mastra npm supply chain campaign (attributed by Microsoft to DPRK/Sapphire Sleet); the SSL certificate issuer WIN-A6QF8AHPQH1\Administrator matches infrastructure from the Mastra operation; C2 traffic to 23.254.167.216 appears in Google Cloud Threat Intelligence's analysis of UNC1069's axios npm attack (April 2026); and the entire operation uses the 23.254.164.0/23 Hostwinds LLC IP range consistent with DPRK-linked activity. This campaign is part of a broader DPRK effort (Contagious Interview) that has targeted five ecosystems — npm, PyPI, Go Modules, crates.io, and Packagist — with 1,700+ malicious packages since January 2025.

Socket.dev's AI Scanner independently detected proc-macro1 as malicious at 07:29:50 UTC on the day of the attack. Nextron Systems separately reported the activity to the Rust Security Response Team, which deleted all malicious versions within approximately two hours (86-107 minutes online per affected crate), locked the compromised droundy account, and restored the yanked legitimate versions. Users are advised to pin affected crates to clean versions, scan Cargo.lock for malicious dependencies, check ~/.cargo/registry/cache for attacker crate artifacts, and treat any system that built a malicious version as potentially compromised — rotating all credentials and secrets accessible to affected build environments.

MITRE ATT&CK techniques used in TL-2026-2085

Collection

T1005 Data from Local System; T1119 Automated Collection

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1553 Subvert Trust Controls

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.004 Command and Scripting Interpreter: Unix Shell; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1573.001 Encrypted Channel: Symmetric Cryptography; T1573.002 Encrypted Channel: Asymmetric Cryptography

Initial Access

T1078 Valid Accounts; T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

Persistence

T1543.001 Create or Modify System Process: Launch Agent; T1543.002 Create or Modify System Process: Systemd Service; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Credential Access

T1555.003 Credentials from Web Browsers

Resource Development

T1583 Acquire Infrastructure; T1583.003 Acquire Infrastructure: Virtual Private Server; T1587.001 Develop Capabilities: Malware; T1588 Obtain Capabilities; T1608.001 Stage Capabilities: Upload Malware

Reconnaissance

T1592 Gather Victim Host Information

Affected products and versions in Popular Rust Crates arrayref, internment, append-only-vec

  • Rust (crates.io) — arrayref
    Vulnerable versions: 0.3.10
    Fixed in: 0.3.9 and prior
  • Rust (crates.io) — internment
    Vulnerable versions: 0.8.7
    Fixed in: 0.8.6 and prior
  • Rust (crates.io) — append-only-vec
    Vulnerable versions: 0.1.9
    Fixed in: 0.1.8 and prior
  • Rust (crates.io) — proc-macro1 (typosquat)
    Vulnerable versions: all versions
    Fixed in: deleted from registry
  • Rust (crates.io) — proc-macro-en (attacker-controlled)
    Vulnerable versions: all versions
    Fixed in: deleted from registry
  • Hostwinds LLC — VPS infrastructure (23.254.164.0/23)
    Vulnerable versions: C2 servers at 23.254.165.112, 23.254.167.107, 23.254.167.216

Remediation for Popular Rust Crates arrayref, internment, append-only-vec

Patches

  • Pin arrayref to <= 0.3.9 (clean version)
  • Pin internment to <= 0.8.6 (clean version)
  • Pin append-only-vec to <= 0.1.8 (clean version)
  • Add explicit proc-macro2 dependency pinned to known-good version if not already present

Immediate actions

  • Check Cargo.lock for malicious crate versions (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9) and six attacker-controlled crate names (proc-macro1, proc-macro-en, aovine, arone, aronenao, tinymember)
  • Search ~/.cargo/registry/cache for attacker crate files using SHA-256 hashes
  • Block 23.254.164.0/23 IP range at perimeter firewalls and on developer endpoints
  • Add Suricata/Snort rules to detect beaconing to /49890878 endpoint
  • Treat any system that built a malicious version as fully compromised — disconnect from network and initiate incident response

Workarounds

  • Audit all Cargo.lock files before any build in CI/CD pipelines
  • Run cargo audit or cargo deny in CI with dependency allowlists
  • Use RustSec advisory-db integration to detect known-vulnerability dependencies
  • Consider implementing build-time network monitoring for unexpected outbound connections from build.rs scripts

Longer-term hardening

  • Deploy software composition analysis (SCA) tooling with automated dependency scanning
  • Implement dependency pinning for all production crates
  • Use vendored/in-tree dependencies for critical crates
  • Enforce code review on all Cargo.toml dependency additions
  • Deploy runtime detection for unexpected build.rs network connections during cargo builds

Weaknesses (CWE) in Popular Rust Crates arrayref, internment, append-only-vec

CWE-494, CWE-829, CWE-1104, CWE-506, CWE-912

Timeline of Popular Rust Crates arrayref, internment, append-only-vec

Showing the 20 most recent tracked events.

  • RustSec publishes RUSTSEC-2026-0260, categorizing arrayref 0.3.10 as malicious with no patched version and no confirmed evidence of in-the-wild usage.
  • 09:09 UTC — blake3 1.8.7 ships without the arrayref dependency, removing transitive exposure for blake3's downstream users.
  • 08:03 UTC — Cleanup begins: proc-macro1 deleted from the crates.io index.
  • 07:54 UTC — Incident reported to the Rust Security Response Team by GitHub user jhobern; RustSec advisory-db issue filed.
  • Within 24 seconds of publishing arrayref 0.3.10, the attacker script-yanked versions 0.3.5-0.3.9, leaving 0.3.10 as the only installable release.
  • 07:11 UTC — proc-macro1 1.0.107 published, adding base64, rustls, and ureq as build-dependencies to form a complete downloader toolkit inside build.rs.
  • 01:17-01:25 UTC — GitHub account 'dtolney' and matching crates.io impersonation account (user ID 438608) created, one transposed letter from legitimate author dtolnay; forged author metadata uses email rchaitm@gmail.com.
  • Wiz Research publishes attribution analysis linking the attack to North Korean state-sponsored group Sapphire Sleet (UNC1069) based on C2 endpoint, SSL certificate, and IP range overlap with the Mastra npm supply chain campaign
  • Rust Security Response Team deletes all six attacker-controlled crates (proc-macro1, proc-macro-en, aovine, arone, aronenao, tinymember), locks compromised droundy account, and restores yanked legitimate versions
  • append-only-vec@0.1.9 deleted from crates.io at 09:25:24 UTC (107 minutes online)
  • internment@0.8.7 deleted from crates.io at 09:04:11 UTC (90 minutes online)
  • arrayref@0.3.10 deleted from crates.io at 08:41:40 UTC (86 minutes online)
  • Rust Security Response Team receives initial report at 07:15 UTC and begins verification and response
  • append-only-vec@0.1.9 malicious version published at 07:37:49 UTC
  • internment@0.8.7 malicious version published at 07:34:07 UTC
  • Socket.dev AI Scanner independently detects proc-macro1 as malicious at 07:29:50 UTC; Nextron Systems separately identifies and reports the attack to the Rust Security Response Team
  • arrayref@0.3.10 published to crates.io at 07:15:00 UTC with injected dependency on typosquat proc-macro1@1.0.107
  • Attacker yanks legitimate arrayref versions 0.3.5 through 0.3.9 to steer dependency resolution toward the upcoming malicious release
  • Attacker compromises maintainer droundy's crates.io credentials, gains administrative access to arrayref, internment, and append-only-vec
  • Attacker publishes proc-macro1@1.0.106 (clean staging copy of proc-macro2) to crates.io under forged identity dtolney

Update history for TL-2026-2085

Sources cited for Popular Rust Crates arrayref, internment, append-only-vec

Detection coverage for TL-2026-2085

As of 2026-08-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2085 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
35 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2085

8 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats