# Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via proc-macro1 Typosquat (DPRK/Sapphire Sleet)

> On August 20, 2026, three legitimate Rust crates (arrayref, internment, append-only-vec) maintained by David Roundy (droundy) were compromised via a typosquat dependency proc-macro1 impersonating proc-macro2. During Cargo builds, proc-macro1's build.rs downloads and executes a cross-platform stage-2 backdoor capable of browser credential theft, persistence (systemd/LaunchAgent/Run key), and HTTPS C2 beaconing. The Rust Security Response Team confirmed the maintainer's account was compromised and remediated within ~2 hours. Wiz Research attributes the attack to North Korean state-sponsored group Sapphire Sleet (UNC1069) based on C2 infrastructure overlap with the Mastra npm campaign. arrayref has ~152M+ clean downloads; the malicious versions were online for 86-107 minutes.

- **Published:** 2026-08-20T00:00:00Z
- **Last reviewed:** 2026-08-21T00:26:14.616Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2085
- **ID:** TL-2026-2085
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** APT38 (North Korea)
- **Detections:** 9 · **IOCs:** 35 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On August 20, 2026, a coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy (crates.io user droundy): arrayref (a widely used macro for safe array referencing, ~152M+ downloads), internment (an interning library), and append-only-vec (an append-only vector). The attacker gained access to the maintainer's crates.io account through compromised credentials, then published malicious versions (arrayref@0.3.10, internment@0.8.7, append-only-vec@0.1.9) that each added a single typosquat dependency: proc-macro1, impersonating the legitimate and widely used proc-macro2 crate (154M+ downloads). The attacker also yanked legitimate versions of arrayref (0.3.5-0.3.9) to steer dependency resolution toward the malicious release.

The typosquat proc-macro1 crate was published by a forged identity (dtolney, with the email rchaitm@gmail.com) and replicated the genuine proc-macro2 source code as camouflage. Its Cargo.toml metadata forged the author as David Tolnay and linked to a non-existent GitHub repository. The malicious logic resided entirely in build.rs, which executes automatically during cargo build — no import or explicit function call by the application is needed. The build.rs reconstructs C2 addresses from Base64-encoded fragments, disables TLS certificate validation via a custom AcceptAll ServerCertVerifier, detects the victim's OS and architecture, and downloads a platform-specific stage-2 payload from 23.254.165.112:9089. On Unix systems it writes /tmp/rust-setup, sets executable permissions, and spawns it detached. On Windows it writes %TEMP%\rust-setup.ps1 plus a VBS launcher and executes via wscript.exe with hidden PowerShell ExecutionPolicy Bypass and CREATE_NO_WINDOW, using std::mem::forget to escape Cargo's job object.

The stage-2 backdoor (analyzed across four platform-specific variants — Linux x86-64, Windows x86-64, macOS x86-64, macOS ARM64) shares a common protocol, configuration structure, AES-128-GCM encryption (hardcoded key 'i am botking'), and RSA-2048 command authentication. It performs host profiling (username, hostname, OS, architecture, privilege level, installed applications), inventories Chromium-based browsers (Chrome, Brave, Edge) for visited login origins and extension identifiers, and establishes C2 beaconing via HTTPS POST to /49890878. The backdoor supports four commands: kill, minicfg (reconfigure C2/beacon interval), startup (install persistence), and runscript (download and execute arbitrary scripts). Persistence mechanisms are OS-specific: Windows HKCU Run key, Linux systemd user service, macOS LaunchAgent. When primary C2 is unreachable, the implant falls back to a Domain Generation Algorithm producing ten deterministic .com domains rotated every 5 days.

Wiz Research attributes the attack to North Korean state-sponsored group Sapphire Sleet (also tracked as UNC1069 by Google/Mandiant and BlueNoroff) based on multiple infrastructure overlaps: the C2 endpoint /49890878 was previously used in the Mastra npm supply chain campaign (attributed by Microsoft to DPRK/Sapphire Sleet); the SSL certificate issuer WIN-A6QF8AHPQH1\Administrator matches infrastructure from the Mastra operation; C2 traffic to 23.254.167.216 appears in Google Cloud Threat Intelligence's analysis of UNC1069's axios npm attack (April 2026); and the entire operation uses the 23.254.164.0/23 Hostwinds LLC IP range consistent with DPRK-linked activity. This campaign is part of a broader DPRK effort (Contagious Interview) that has targeted five ecosystems — npm, PyPI, Go Modules, crates.io, and Packagist — with 1,700+ malicious packages since January 2025.

Socket.dev's AI Scanner independently detected proc-macro1 as malicious at 07:29:50 UTC on the day of the attack. Nextron Systems separately reported the activity to the Rust Security Response Team, which deleted all malicious versions within approximately two hours (86-107 minutes online per affected crate), locked the compromised droundy account, and restored the yanked legitimate versions. Users are advised to pin affected crates to clean versions, scan Cargo.lock for malicious dependencies, check ~/.cargo/registry/cache for attacker crate artifacts, and treat any system that built a malicious version as potentially compromised — rotating all credentials and secrets accessible to affected build environments.

## MITRE ATT&CK

- T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools
- T1078 Valid Accounts
- T1204.002 User Execution: Malicious File
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1543.001 Create or Modify System Process: Launch Agent
- T1543.002 Create or Modify System Process: Systemd Service
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1555.003 Credentials from Web Browsers
- T1082 System Information Discovery
- T1518 Software Discovery
- T1005 Data from Local System
- T1071.001 Application Layer Protocol: Web Protocols
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1573.002 Encrypted Channel: Asymmetric Cryptography
- T1568.002 Dynamic Resolution: Domain Generation Algorithms
- T1587.001 Develop Capabilities: Malware
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1608.001 Stage Capabilities: Upload Malware
- T1553 Subvert Trust Controls
- T1083 File and Directory Discovery
- T1119 Automated Collection
- T1041 Exfiltration Over C2 Channel
- T1583 Acquire Infrastructure
- T1588 Obtain Capabilities
- T1592 Gather Victim Host Information

## Sources

- [Rust Security Response Team: Supply Chain Attack on arrayref](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/)
- [Socket.dev: Popular Rust Crates Compromised in Build-Time Supply Chain Attack](https://socket.dev/blog/popular-rust-crates-compromised)
- [Wiz Research: Rust Supply Chain Attack on arrayref — Significant Overlap with DPRK Campaigns](https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns)
- [RustSec Advisory DB — Issue 3161: arrayref supply chain attack via proc-macro1](https://github.com/rustsec/advisory-db/issues/3161)
- [Aikido.dev: Compromised Rust Crate onering Performs Code Exfiltration (related incident)](https://www.aikido.dev/blog/compromised-rust-crate-onering-performs-code-exfiltration)
- [Microsoft: DPRK Sapphire Sleet Mastra npm supply chain attack](https://www.microsoft.com/en-us/security/blog/2026/06/17/sapphire-sleet-mastra-npm-supply-chain/)
- [Mandiant: UNC1069 multi-ecosystem supply chain campaigns](https://www.mandiant.com/resources/unc1069-contagious-interview-ecosystem-supply-chain)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2085
