wiz · Crawled Sep 1, 2026
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
29 IoCs 1 Actors
Read original article ↗
AI Summary
A supply chain attack was conducted against the Rust ecosystem by compromising the maintainer account of widely used crates, including arrayref, internment, and append-only-vec. Malicious versions were published with a typosquatted dependency, proc-macro1, which executes a build script to download and run a second-stage payload. The payload acts as a backdoor, exfiltrating system information, enumerating browser login data, and enabling remote command execution, with infrastructure and TTPs showing significant overlap with DPRK-linked campaigns such as Mastra and UNC1069.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 29 extracted
| Type | Value | Detail |
|---|---|---|
| Package | arrayref@0.3.10 | Details → |
| Package | internment@0.8.7 | Details → |
| Package | append-only-vec@0.1.9 | Details → |
| Package | proc-macro1 | Details → |
| Package | proc-macro-en | Details → |
| Package | aovine | Details → |
| Package | arone | Details → |
| Package | aronenao | Details → |
| Package | tinymember | Details → |
| SHA-256 | 25ad700976873c76af785cb99b33c48db7df8b81f21d1e9e06b3676b9a9373ae | Details → |
| SHA-256 | 61198155da51b838772eecf5bfaac6cbc4dcc388dccc56658fc28a8e831b34d4 | Details → |
| SHA-256 | b5c1b5b0763a8809a644a8f92224653f0aca623a98eecc714d27f74b80fbe436 | Details → |
| SHA-1 | f22e3e01e38bcdf001f0d15a2dbfdec5a1cf8eff | Details → |
| SHA-1 | f4767ad92cb61401fd69139cade563501c39b991 | Details → |
| SHA-1 | fc0fdb978eac72f4484b48db058e4473f1bc516e | Details → |
| SHA-1 | ff7e20cf642346bf893f1eca808df82035bb53d0 | Details → |
| IP | 23[.]254[.]165[.]112:9089 | Details → |
| IP | 23[.]254[.]165[.]112:443 | Details → |
| IP | 23[.]254[.]167[.]107:443 | Details → |
| Domain | hwsrv-798836[.]hostwindsdns[.]com | Details → |
| Filename | /tmp/rust-setup | Details → |
| Filename | %TEMP%\rust-setup.ps1 | Details → |
| Filename | %TEMP%\rust-setup-launch.vbs | Details → |
| Filename | rust-crate_0.1.0 | Details → |
| Filename | rust-crate_0.2.0 | Details → |
| Filename | rust-crate_0.3.0 | Details → |
| Filename | rust-crate_0.4.0 | Details → |
| Registry User | dtolney | Details → |
| rchaitm[@]gmail[.]com | Details → |
MITRE ATT&CK TTPs 53 techniques
T1001 Data Obfuscation · Command And Control T1003 OS Credential Dumping · Credential Access T1018 Remote System Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1021.004 SSH · Lateral Movement T1021.006 Windows Remote Management · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1029 Scheduled Transfer · Exfiltration T1036.005 Match Legitimate Name or Location · Defense Evasion T1040 Network Sniffing · Credential Access T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1057 Process Discovery · Discovery T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1070.001 Clear Windows Event Logs · Defense Evasion T1070.004 File Deletion · Defense Evasion T1070.006 Timestomp · Defense Evasion T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1085 T1085 T1087 Account Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1134 Access Token Manipulation · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1195.002 Compromise Software Supply Chain · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1218 System Binary Proxy Execution · Defense Evasion T1218.011 Rundll32 · Defense Evasion T1480 Execution Guardrails · Defense Evasion T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1495 Firmware Corruption · Impact T1534 Internal Spearphishing · Lateral Movement T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1557 Adversary-in-the-Middle · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access T1566.002 Spearphishing Link · Initial Access T1583 Acquire Infrastructure · Resource Development T1610 Deploy Container · Defense Evasion