Threat reportSupply ChainTL-2026-2086

Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked Backdoor

criticalACTIVE

Rust Supply Chain Attack on arrayref (TL-2026-2086), also tracked as arrayref supply chain compromise, is a critical-severity supply-chain compromise, first published 2026-08-20. It is attributed to APT38 (North Korea) with high confidence, affects Rust Ecosystem (crates.io) arrayref crate, maps to 18 MITRE ATT&CK techniques (T1027, T1059.001, T1059.004), and is covered by 9 detection rules and 34 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
2APT38
Detection rules
9SPL · KQL · Sigma
IOCs
34Indicators of compromise

Key facts for TL-2026-2086

Threat ID
TL-2026-2086
Also known as
arrayref supply chain compromise, proc-macro1 typosquat campaign, dtolney campaign
Severity
CRITICAL
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
APT38, UNC1069
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
technology, software-development, blockchain, cryptocurrency, finance
Target regions
Global
Detection rules
9
Indicators of compromise
34

Malware and tooling in Rust Supply Chain Attack on arrayref

Malware and tooling: systemd, WIN-A6QF8AHPQH1\Administrator@WIN-A6QF8AHPQH1

How Rust Supply Chain Attack on arrayref works

On August 20, 2026, the popular Rust crate arrayref (present in 35%+ of all environments) and two sibling crates (internment, append-only-vec) were hijacked via compromised maintainer credentials and republished with a typosquatted dependency (proc-macro1) that executes a compile-time backdoor. The second-stage implant exfiltrates browser credentials, establishes cross-platform persistence, and beacons to C2 over HTTPS to Hostwinds infrastructure. Attribution to North Korea (Sapphire Sleet / UNC1069) is robust based on shared C2 endpoints and SSL infrastructure with the Mastra and axios npm supply chain attacks.

On August 20, 2026, at approximately 07:15 UTC, an attacker using the crates.io impersonation account 'dtolney' published malicious version 0.3.10 of the legitimate arrayref crate. The legitimate maintainer (droundy) had their machine or credentials compromised — the crate source code was not directly altered, but a single dependency line was injected into Cargo.toml. Within minutes, the same attacker published compromised versions of internment (0.8.7 at 07:34 UTC) and append-only-vec (0.1.9 at 07:37 UTC). The legitimate maintainer's account was subsequently locked as a precaution.

The injected dependency 'proc-macro1' is a typosquat of the legitimate and widely used proc-macro2 crate (154M+ total downloads). This was the first dependency added to arrayref in its ten-year history. When any Rust project depending on the compromised crate executes cargo build, proc-macro1's build.rs runs automatically at compile time. The build script reconstructs a C2 URL from Base64-obfuscated fragments pointing to a Hostwinds VPS at 23.254.165.112:9089, disables TLS certificate validation via a custom AcceptAll verifier, detects the victim's OS and architecture, downloads a platform-specific stage-2 payload, writes it to disk (/tmp/rust-setup on Unix or %TEMP%\rust-setup.ps1 on Windows), and executes it. Critically, the build script uses std::mem::forget(child) to escape Cargo's job object, ensuring the backdoor continues running after the build exits with code 0. The crate otherwise functions normally, making detection difficult.

The stage-2 implant — retrieved by Wiz Research via Google Threat Intelligence — is a full-featured cross-platform backdoor. It beacons to C2 via HTTPS POST to the /49890878 endpoint, exfiltrating host information and stolen credentials as Base64-encoded JSON. It enumerates saved logins from Chrome, Brave, and Edge browser SQLite databases (noting the queries enumerate saved logins but do not retrieve encrypted credentials). Persistence is achieved through Registry Run keys (Windows), LaunchAgents (macOS), or systemd user services (Linux). On Linux, post-infection artifacts include the directories $HOME/.config/AzureKits and $HOME/.config/ServiceKit with executables MonoService and MonoXpc. The implant supports four C2 commands: kill (terminate), minicfg (reconfigure C2 and beacon interval), startup (install persistence), and runscript (download and execute arbitrary PowerShell or shell scripts, synchronously or in background). If the primary C2 becomes unreachable, a Domain Generation Algorithm (DGA) generates 10 algorithmic .com domains every 5 days as fallback. All configuration is encrypted with AES-128-GCM using the hardcoded key 'i am botking', and commands are authenticated via an embedded RSA-2048 private key.

Attribution to North Korea is well-substantiated. The beacon path /49890878 was previously used in the Mastra npm supply chain campaign, attributed by Microsoft with high confidence to Sapphire Sleet (a DPRK state actor under the Reconnaissance General Bureau / Lab 110). The SSL certificate issuer WIN-A6QF8AHPQH1\Administrator@WIN-A6QF8AHPQH1 matches infrastructure on IP 23.254.167.13 used in the same Mastra campaign. A victim-reported C2 address 23.254.167.216 appears in Google Cloud Threat Intelligence's analysis of UNC1069's axios npm attack (March 2026), which Mandiant attributes to North Korea. Both campaigns share the same Hostwinds LLC range 23.254.164.0/23 (AS54290, Seattle). The actor further participates in the broader 'Contagious Interview' cross-ecosystem supply chain operation, which has published over 1,700 malicious packages across npm, PyPI, crates.io, Go Modules, and Packagist since January 2025.

The Rust Security Response Team was alerted by researchers at Nextron Systems. The team deleted all malicious crate versions and locked the maintainer's account. Exposure windows ranged from 86 minutes (arrayref) to 107 minutes (append-only-vec). Despite the rapid response, arrayref's pervasive usage (75% of Rust-present environments) makes this the largest Rust crate compromise by download count to date. Notably, because the malicious versions were deleted rather than merely yanked, cargo audit does not flag affected projects — a critical detection gap that makes network-level egress monitoring essential.

MITRE ATT&CK techniques used in TL-2026-2086

Defense Evasion

T1027 Obfuscated Files or Information

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.004 Command and Scripting Interpreter: Unix Shell; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1568 Dynamic Resolution; T1571 Non-Standard Port; T1573.001 Encrypted Channel: Symmetric Cryptography

Discovery

T1082 System Information Discovery; T1518 Software Discovery

Initial Access

T1195 Supply Chain Compromise; T1195.001 Compromise Software Dependencies and Development Tools; T1195.002 Compromise Software Supply Chain

Persistence

T1543.001 Create or Modify System Process: Launch Agent; T1543.002 Create or Modify System Process: Systemd Service; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Credential Access

T1555.003 Credentials from Web Browsers

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Rust Supply Chain Attack on arrayref

  • Rust Ecosystem (crates.io) — arrayref crate
    Vulnerable versions: 0.3.10
    Fixed in: 0.3.9 and earlier
  • Rust Ecosystem (crates.io) — internment crate
    Vulnerable versions: 0.8.7
    Fixed in: 0.8.6 and earlier
  • Rust Ecosystem (crates.io) — append-only-vec crate
    Vulnerable versions: 0.1.9
    Fixed in: 0.1.8 and earlier
  • Hostwinds LLC — VPS Infrastructure (AS54290, 23.254.164.0/23)
    Vulnerable versions: entire /23 range
  • Mozilla / Rust Foundation — crates.io package registry
    Vulnerable versions: all crates.io versions
    Fixed in: malicious artifacts deleted; no registry fix necessary

Remediation for Rust Supply Chain Attack on arrayref

Patches

  • No vendor patch available (malicious versions deleted from crates.io; pin to arrayref 0.3.9, internment 0.8.6, append-only-vec 0.1.8 or earlier)

Immediate actions

  • Scan all Cargo.lock files for compromised versions: arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9
  • Scan ~/.cargo/registry/cache for all six attacker-controlled crate artifacts: proc-macro1, proc-macro-en, aovine, arone, aronenao, tinymember
  • Treat any host that ran cargo build with the affected crates as fully compromised; rotate every credential, API token, CI/CD secret, and code-signing key from a clean machine
  • Reset browser-saved credentials for Chrome, Brave, and Edge; revoke active sessions and API tokens
  • Block C2 infrastructure: 23.254.165.112, 23.254.167.107, 23.254.167.216, 23.254.164.0/23 at network perimeter
  • Remove persistence artifacts: check for $HOME/.config/AzureKits, $HOME/.config/ServiceKit, MonoService, MonoXpc on Linux; HKCU Run keys on Windows; LaunchAgents on macOS; systemd user services on Linux
  • Rebuild all artifacts produced during the 07:15–09:25 UTC window on August 20, 2026 from clean sources

Workarounds

  • Audit dependencies manually in Cargo.toml before building
  • Use cargo vet or cargo crev for third-party code review
  • Set CARGO_NET_OFFLINE=true to prevent new download-based dependency resolution during build

Longer-term hardening

  • Implement build-time dependency auditing to flag unexpected new dependencies (especially networking crates like ureq, reqwest, rustls in crates with no networking purpose)
  • Pin dependency versions in Cargo.lock and review changes on upgrade; do not blindly resolve yanked versions
  • Run cargo build in sandboxed or network-restricted CI environments where possible
  • Adopt software bill of materials (SBOM) generation for Rust projects via cargo-audit and cargo-deny
  • Monitor crates.io for typosquatting of commonly used proc-macro and utility crates
  • Use network-level egress monitoring to detect connections to anomalous external IPs from build processes

Weaknesses (CWE) in Rust Supply Chain Attack on arrayref

CWE-494: Download of Code Without Integrity Check, CWE-506: Embedded Malicious Code, CWE-1104: Use of Unmaintained Third Party Components

Timeline of Rust Supply Chain Attack on arrayref

  • The 'Contagious Interview' cross-ecosystem supply chain campaign begins; over 1,700 malicious packages subsequently published across npm, PyPI, crates.io, Go Modules, and Packagist by DPRK-linked actors
  • UNC1069 compromises the axios npm package via stolen classic npm access token; publishes malicious versions 1.14.1 and 0.30.4 with plain-crypto-js dependency deploying WAVESHAPER.V2 backdoor across Windows, macOS, and Linux; 169-minute exposure window
  • Sapphire Sleet publishes clean bait version easy-day-js@1.11.21 (typosquatting dayjs, 57M+ weekly downloads) as first phase of Mastra npm supply chain compromise
  • Microsoft publishes analysis of Mastra npm supply chain compromise, attributing with high confidence to Sapphire Sleet (DPRK); shared C2 infrastructure (23.254.164.0/23, /49890878 endpoint) later linked to Rust supply chain attack
  • Sapphire Sleet publishes weaponized easy-day-js@1.11.22 and mass-poisoned versions of 140+ @mastra packages via compromised ehindero account; postinstall hook deploys Node.js tasking implant with cryptocurrency wallet targeting (166 wallet extensions)
  • StepSecurity publishes runtime detection analysis showing Harden-Runner flagged anomalous connection to 23.254.165.112:9089 at 09:07:27 UTC; documents std::mem::forget(child) job object escape technique in build.rs
  • Wiz Research (Rami McCarthy, Benjamin Read) publishes detailed analysis with stage-2 payload reversing via Google Threat Intelligence; documents DPRK attribution evidence including shared C2 endpoint /49890878 with Mastra campaign, shared SSL issuer, and overlapping Hostwinds infrastructure
  • Rust Foundation publishes advisory confirming supply chain attack; maintainer droundy's account locked; all six attacker-owned crates (proc-macro1, proc-macro-en, aovine, arone, aronenao, tinymember) deleted
  • Malicious append-only-vec 0.1.9 deleted from crates.io after 107-minute exposure window (07:37-09:25 UTC)
  • Malicious internment 0.8.7 deleted from crates.io after 90-minute exposure window (07:34-09:04 UTC)
  • Malicious arrayref 0.3.10 deleted from crates.io after 86-minute exposure window (07:15-08:41 UTC)
  • Nextron Systems researchers detect proc-macro1 as malicious and report to the Rust Security Response Team; investigation confirms widespread supply chain compromise
  • Malicious append-only-vec 0.1.9 published to crates.io by the same attacker
  • Malicious internment 0.8.7 published to crates.io by the same attacker
  • Malicious arrayref 0.3.10 published to crates.io via compromised maintainer (droundy) account; attacker impersonation account dtolney adds proc-macro1 typosquat dependency — the first dependency in arrayref's ten-year history

Sources cited for Rust Supply Chain Attack on arrayref

Detection coverage for TL-2026-2086

As of 2026-08-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2086 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
34 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2086

13 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats