A supply-chain attack hit the Rust ecosystem after arrayref 0.3.10 was published with a dependency on proc-macro1 1.0.107, a typosquatted package impersonating proc-macro2. The malicious crate used a build.rs script to download and execute a second-stage payload during compilation, meaning developers and CI systems could be compromised simply by building an affected project. Rust maintainers said they received a report at 07:15 UTC and removed the malicious packages, including related crates such as proc-macro-en, aovine, arone, aronenao, and tinymember, while also restoring or yanking affected versions of arrayref, internment, and append-only-vec.
Investigators said the payload infrastructure contacted 23.254.165.112 over ports 9089 and 443, bypassed TLS certificate validation, selected platform-specific malware for Unix and Windows, and allowed builds to appear normal after execution. The campaign appears to have used a fake dtolney account to mimic Rust maintainer David Tolnay and likely leveraged a compromised publisher account for arrayref; crates.io locked the affected author account as a precaution. Because arrayref is widely used and can reach downstream projects through dependencies such as tiny-skia, sctk-adwaita, and winit, maintainers warned that Rust GUI applications and other software stacks may have been exposed, and advised users to inspect Cargo caches and lockfiles, treat affected hosts as compromised, rotate credentials, and rebuild artifacts from clean sources.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
Wiz disclosed technical details of the second-stage payload delivered by proc-macro1, including host reconnaissance, browser data collection, persistence on Windows/macOS/Linux, remote command execution, and DGA fallback behavior. The report also published indicators such as C2 infrastructure, POST path, malicious crate names, and payload file paths tied to the campaign.
Wiz reported that infrastructure used in the Rust crate supply-chain attack overlapped with recent DPRK-linked software supply-chain campaigns, including Mastra and axios. The report stopped short of definitive attribution but introduced a new suspected actor link for the incident.
crates.io locked the affected author account and stated it did not believe the arrayref maintainer acted maliciously, assessing instead that the maintainer's computer or credentials were likely compromised.
The response team deleted related malicious crates including proc-macro-en, aovine, arone, aronenao, and tinymember; deleted malicious versions of internment and append-only-vec; and restored previously maliciously yanked arrayref versions.
Reporting on the crates.io incident stated that malicious arrayref 0.3.10 remained available from 10:15 to 11:41 MSK and was downloaded 53 times before removal. The same report said no confirmed successful compromise had been identified at that time.
crates.io removed arrayref 0.3.10 from the index, ending availability of the compromised release after an exposure window of roughly 86 minutes.
crates.io deleted proc-macro1 after the report, removing the typosquatted malicious crate from the registry.
After receiving the report, the Rust Security Response Team confirmed proc-macro1 was malicious and discovered that the popular arrayref crate had been republished to depend on it.
The Rust Security Response Team received a report that proc-macro1 was malicious, and the incident was also reported to the RustSec advisory database and Rust security contacts.
The Rust Security Response Team said the Research Team at Nextron Systems GmbH initially discovered the malicious proc-macro1 crate and reported it to the project. This newly identifies the external researchers who first surfaced the incident.
Versions 0.3.5 through 0.3.9 of arrayref were yanked under the owner account, creating pressure for users to upgrade toward the malicious 0.3.10 release.
append-only-vec 0.1.9 was published with a malicious Cargo.toml change that added a dependency on proc-macro1 1.0.107, extending the Rust supply-chain attack beyond arrayref. Building dependent projects could trigger proc-macro1's malicious build.rs and execute attacker code.
internment 0.8.7 was published from the droundy account with a dependency on proc-macro1 1.0.107, adding another legitimate Rust crate to the build-time supply-chain attack. The malicious dependency caused Cargo builds of affected projects to execute proc-macro1's build.rs and fetch attacker payloads.
arrayref 0.3.10 was published from the droundy account and introduced its first-ever dependency on proc-macro1 1.0.107, making builds of affected projects execute the malicious chain.
proc-macro1 1.0.107 was published with a malicious build.rs script that downloaded and executed a remote payload during compilation while masquerading as a legitimate dependency.
The attacker published proc-macro1 1.0.106 as a clean copy of proc-macro2, apparently to stage the later typosquatting attack.
A crates.io account named dtolney was created shortly after the fake GitHub account, establishing the publisher identity later used for the proc-macro1 typosquat.
A GitHub account named dtolney was created to impersonate proc-macro2 author David Tolnay as part of the typosquatting setup for the malicious Rust crate campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourceopennet.ru
Open sourceopennet.me
Open sourcebleepingcomputer.com
Open sourceblog.rust-lang.org
Open sourcesemgrep.dev
Open sourceblog.rust-lang.org
Open sourcesafedep.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.