Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper
AI Summary
A supply-chain attack compromised the Rust crate ecosystem through a poisoned build-time dependency in three legitimate crates: arrayref, internment, and append-only-vec. The attacker hijacked a maintainer's account and used a typosquatted crate, proc-macro1, to deliver a malicious build script that downloads and executes a second-stage payload during compilation. The dropper connects to C2 infrastructure hosted on Hostwinds IP addresses, enabling remote code execution without any runtime code changes. The attack leveraged a 'yank-and-upgrade' tactic to lure developers into updating to the malicious version. Six attacker-owned crates were deleted, including a backup dropper (proc-macro-en), and the exposure window lasted from 07:11 to 09:25 UTC on August 20, 2026.
AI-extracted · verify before operational use
Indicators of Compromise 19 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 23[.]254[.]165[.]112 | Details → |
| IP | 23[.]254[.]167[.]107 | Details → |
| IP | 23[.]254[.]167[.]216 | Details → |
| Domain | hwsrv-798836[.]hostwindsdns[.]com | Details → |
| SHA-256 | 25ad700976873c76af785cb99b33c48db7df8b81f21d1e9e06b3676b9a9373ae | Details → |
| SHA-256 | 61198155da51b838772eecf5bfaac6cbc4dcc388dccc56658fc28a8e831b34d4 | Details → |
| SHA-256 | b5c1b5b0763a8809a644a8f92224653f0aca623a98eecc714d27f74b80fbe436 | Details → |
| Filename | /tmp/rust-setup | Details → |
| Filename | rust-setup.ps1 | Details → |
| Filename | rust-setup-launch.vbs | Details → |
| Package | arrayref@0.3.10 | Details → |
| Package | internment@0.8.7 | Details → |
| Package | append-only-vec@0.1.9 | Details → |
| Package | proc-macro1 | Details → |
| Package | proc-macro-en | Details → |
| Package | aovine | Details → |
| Package | arone | Details → |
| Package | aronenao | Details → |
| Package | tinymember | Details → |