Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ces versions ajoutent une dépendance typosquattée (proc-macro1, imitant le légitime proc-macro2). Le script de build build.rs de proc-macro1 exécute la charge malveillante au moment de la compilation.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Hackers compromised the maintainer account for the widely used Rust crate arrayref to introduce malware that executed on developers’ systems during compilation... Within a 23-minute window, the attacker also poisoned two other crates, append-only-vec and internment, in the same supply-chain attack.
Version 0.3.10 kept the macro source byte for byte and added a single line to the manifest: [dependencies] proc-macro1 = "1.0.107"
This rogue package took advantage of the automated build process in the Rust package manager, cargo, downloading and executing an unauthorized payload in the background... because build scripts run during compilation, building an affected project was sufficient to execute the payload.
Cargo compiles and runs build scripts automatically during compilation, so resolving the dependency was enough.
Écrit le payload dans /tmp/rust-setup (Unix) ou %TEMP%\rust-setup.ps1 (Windows) Exécute le payload en lui passant l’adresse C2 comme argument
Télécharge un payload spécifique à la plateforme... Écrit le payload dans /tmp/rust-setup (Unix)... Exécute le payload en lui passant l’adresse C2 comme argument
On Windows it writes a PowerShell script and a VBScript launcher under %TEMP% and starts them hidden... let child = Command::new("wscript.exe")
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.