Multiple Rust packages were removed from crates.io after a supply-chain attack introduced malicious dependencies into popular crates including arrayref 0.3.10, append-only-vec 0.1.9, and internment 0.8.7. The compromised releases added a direct dependency on the rogue crate proc-macro1, while a second malicious crate, proc-macro-en, was also published as part of the same campaign. RustSec said the malicious versions were available for roughly 86 to 107 minutes before removal, with arrayref alone downloaded 2,285 times during that window; the related publisher account for proc-macro-en was locked, and no patched versions were issued because the packages were classified as malicious rather than conventionally vulnerable.

Trace attribution and downstream blast radius.
12 events from the most recent confirmed update back to the earliest known activity.
Wiz Research published an analysis on 2026-08-20 assessing that the crates.io supply-chain campaign likely had North Korea links, citing infrastructure overlaps with the Mastra campaign and the npm axios attack associated with UNC1069. The report, informed in part by Google Threat Intelligence context, tied the activity to shared Hostwinds infrastructure and reused C2 characteristics.
RustSec reported and issued advisories covering the malicious crates and compromised dependent releases, including arrayref, append-only-vec, internment, and proc-macro-en. The advisories classified the incidents as malicious supply-chain issues.
In response to the malicious publication, proc-macro-en was removed from crates.io and the related user account was locked. No patched version was provided because the crate was classified as malicious.
The malicious append-only-vec release remained available for about 107 minutes before being removed from crates.io. The advisory stated there was no evidence of actual usage.
The malicious internment release was removed about 90 minutes after publication. The advisory stated there was no evidence of actual usage of the compromised version.
The malicious arrayref release was removed about 86 minutes after publication. RustSec later stated there were no patched versions and that unaffected versions were 0.3.9 and earlier.
A compromised version of internment was published on crates.io with a direct dependency on proc-macro1, introducing the same malicious build-script execution path during builds.
A new compromised version of append-only-vec was published with a direct dependency on proc-macro1, which would execute a malicious build script during the build process.
Within the same minute that malicious arrayref 0.3.10 was published, legitimate arrayref versions 0.3.5 through 0.3.9 were yanked from crates.io. The action would have left the malicious release as the only unyanked recent version and could have pushed developers toward it via Cargo warnings.
A compromised version of arrayref was published with a direct dependency on proc-macro1, causing a malicious build script to execute during Cargo builds. The release was later reported to have been downloaded 2,285 times during its availability window.
A single version of the Rust crate proc-macro-en was published on crates.io as part of the same supply-chain attack associated with proc-macro1. The crate contained the same malicious build script as proc-macro1.
A public analysis documented that proc-macro1 and proc-macro-en used identical malicious build scripts to download platform-specific payloads from 23.254.165.112:9089 and pass 23.254.165.112:443 as the initial C2 endpoint. The report also described the Windows payload as a PowerShell backdoor with host profiling, Chromium data collection, persistence, and remote command execution capabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
7 references tracked. Mallory keeps watching after this page renders.
upwind.io
Open sourcecyberveille.ch
Open sourcerustsec.org
Open sourcerustsec.org
Open sourcerustsec.org
Open sourcerustsec.org
Open sourcegist.github.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.