step-security · Crawled Sep 2, 2026

Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper

19 IoCs
Read original article ↗

AI Summary

A supply-chain attack compromised the Rust crate ecosystem through a poisoned build-time dependency in three legitimate crates: arrayref, internment, and append-only-vec. The attacker hijacked a maintainer's account and used a typosquatted crate, proc-macro1, to deliver a malicious build script that downloads and executes a second-stage payload during compilation. The dropper connects to C2 infrastructure hosted on Hostwinds IP addresses, enabling remote code execution without any runtime code changes. The attack leveraged a 'yank-and-upgrade' tactic to lure developers into updating to the malicious version. Six attacker-owned crates were deleted, including a backup dropper (proc-macro-en), and the exposure window lasted from 07:11 to 09:25 UTC on August 20, 2026.

AI-extracted · verify before operational use

Indicators of Compromise 19 extracted

Type Value Detail
IP 23[.]254[.]165[.]112 Details →
IP 23[.]254[.]167[.]107 Details →
IP 23[.]254[.]167[.]216 Details →
Domain hwsrv-798836[.]hostwindsdns[.]com Details →
SHA-256 25ad700976873c76af785cb99b33c48db7df8b81f21d1e9e06b3676b9a9373ae Details →
SHA-256 61198155da51b838772eecf5bfaac6cbc4dcc388dccc56658fc28a8e831b34d4 Details →
SHA-256 b5c1b5b0763a8809a644a8f92224653f0aca623a98eecc714d27f74b80fbe436 Details →
Filename /tmp/rust-setup Details →
Filename rust-setup.ps1 Details →
Filename rust-setup-launch.vbs Details →
Package arrayref@0.3.10 Details →
Package internment@0.8.7 Details →
Package append-only-vec@0.1.9 Details →
Package proc-macro1 Details →
Package proc-macro-en Details →
Package aovine Details →
Package arone Details →
Package aronenao Details →
Package tinymember Details →