# Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked Backdoor

> On August 20, 2026, the popular Rust crate arrayref (present in 35%+ of all environments) and two sibling crates (internment, append-only-vec) were hijacked via compromised maintainer credentials and republished with a typosquatted dependency (proc-macro1) that executes a compile-time backdoor. The second-stage implant exfiltrates browser credentials, establishes cross-platform persistence, and beacons to C2 over HTTPS to Hostwinds infrastructure. Attribution to North Korea (Sapphire Sleet / UNC1069) is robust based on shared C2 endpoints and SSL infrastructure with the Mastra and axios npm supply chain attacks.

- **Published:** 2026-08-20T00:00:00Z
- **Last reviewed:** 2026-08-20T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2086
- **ID:** TL-2026-2086
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** APT38 (North Korea)
- **Detections:** 9 · **IOCs:** 34 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On August 20, 2026, at approximately 07:15 UTC, an attacker using the crates.io impersonation account 'dtolney' published malicious version 0.3.10 of the legitimate arrayref crate. The legitimate maintainer (droundy) had their machine or credentials compromised — the crate source code was not directly altered, but a single dependency line was injected into Cargo.toml. Within minutes, the same attacker published compromised versions of internment (0.8.7 at 07:34 UTC) and append-only-vec (0.1.9 at 07:37 UTC). The legitimate maintainer's account was subsequently locked as a precaution.

The injected dependency 'proc-macro1' is a typosquat of the legitimate and widely used proc-macro2 crate (154M+ total downloads). This was the first dependency added to arrayref in its ten-year history. When any Rust project depending on the compromised crate executes cargo build, proc-macro1's build.rs runs automatically at compile time. The build script reconstructs a C2 URL from Base64-obfuscated fragments pointing to a Hostwinds VPS at 23.254.165.112:9089, disables TLS certificate validation via a custom AcceptAll verifier, detects the victim's OS and architecture, downloads a platform-specific stage-2 payload, writes it to disk (/tmp/rust-setup on Unix or %TEMP%\rust-setup.ps1 on Windows), and executes it. Critically, the build script uses std::mem::forget(child) to escape Cargo's job object, ensuring the backdoor continues running after the build exits with code 0. The crate otherwise functions normally, making detection difficult.

The stage-2 implant — retrieved by Wiz Research via Google Threat Intelligence — is a full-featured cross-platform backdoor. It beacons to C2 via HTTPS POST to the /49890878 endpoint, exfiltrating host information and stolen credentials as Base64-encoded JSON. It enumerates saved logins from Chrome, Brave, and Edge browser SQLite databases (noting the queries enumerate saved logins but do not retrieve encrypted credentials). Persistence is achieved through Registry Run keys (Windows), LaunchAgents (macOS), or systemd user services (Linux). On Linux, post-infection artifacts include the directories $HOME/.config/AzureKits and $HOME/.config/ServiceKit with executables MonoService and MonoXpc. The implant supports four C2 commands: kill (terminate), minicfg (reconfigure C2 and beacon interval), startup (install persistence), and runscript (download and execute arbitrary PowerShell or shell scripts, synchronously or in background). If the primary C2 becomes unreachable, a Domain Generation Algorithm (DGA) generates 10 algorithmic .com domains every 5 days as fallback. All configuration is encrypted with AES-128-GCM using the hardcoded key 'i am botking', and commands are authenticated via an embedded RSA-2048 private key.

Attribution to North Korea is well-substantiated. The beacon path /49890878 was previously used in the Mastra npm supply chain campaign, attributed by Microsoft with high confidence to Sapphire Sleet (a DPRK state actor under the Reconnaissance General Bureau / Lab 110). The SSL certificate issuer WIN-A6QF8AHPQH1\Administrator@WIN-A6QF8AHPQH1 matches infrastructure on IP 23.254.167.13 used in the same Mastra campaign. A victim-reported C2 address 23.254.167.216 appears in Google Cloud Threat Intelligence's analysis of UNC1069's axios npm attack (March 2026), which Mandiant attributes to North Korea. Both campaigns share the same Hostwinds LLC range 23.254.164.0/23 (AS54290, Seattle). The actor further participates in the broader 'Contagious Interview' cross-ecosystem supply chain operation, which has published over 1,700 malicious packages across npm, PyPI, crates.io, Go Modules, and Packagist since January 2025.

The Rust Security Response Team was alerted by researchers at Nextron Systems. The team deleted all malicious crate versions and locked the maintainer's account. Exposure windows ranged from 86 minutes (arrayref) to 107 minutes (append-only-vec). Despite the rapid response, arrayref's pervasive usage (75% of Rust-present environments) makes this the largest Rust crate compromise by download count to date. Notably, because the malicious versions were deleted rather than merely yanked, cargo audit does not flag affected projects — a critical detection gap that makes network-level egress monitoring essential.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1195.001 Compromise Software Dependencies and Development Tools
- T1195.002 Compromise Software Supply Chain
- T1204.002 User Execution: Malicious File
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1543.001 Create or Modify System Process: Launch Agent
- T1543.002 Create or Modify System Process: Systemd Service
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1555.003 Credentials from Web Browsers
- T1082 System Information Discovery
- T1518 Software Discovery
- T1071.001 Application Layer Protocol: Web Protocols
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1568 Dynamic Resolution
- T1571 Non-Standard Port

## Sources

- [Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns](https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns)
- [Supply Chain Attack on arrayref](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/)
- [Postinstall Payload: Inside the Mastra npm Supply Chain Compromise](https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/)
- [North Korea-Nexus Threat Actor Compromises Widely Used NPM Package Axios](https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package)
- [arrayref Rust Crate Supply Chain Attack — StepSecurity Analysis](https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack)
- [DPRK Contagious Interview Cross-Ecosystem Software Supply Chain Operation](https://labs.cloudsecurityalliance.org/research/csa-research-note-dprk-contagious-interview-cross-ecosystem/)
- [From 114,000 OSS Artifacts to 100 Analyst Reviews a Day with THOR Thunderstorm](https://www.nextron-systems.com/2026/06/19/oss-artifact-scanning-at-scale/)
- [Microsoft Links Mastra AI Supply Chain Attack to North Korean Hackers](https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/)
- [A Forgotten Contributor Account Compromised: The Entire Mastra npm Package Scope](https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/)
- [Two Popular Rust Crates Compromised in Supply Chain Attack](https://www.aikido.dev/blog/two-popular-rust-crates-arrayref-and-append-only-vec-compromised-in-supply-chain-attack)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2086
