1w ago · step-security
A supply-chain attack compromised the Rust crate ecosystem through a poisoned build-time dependency in three legitimate crates: arrayref, internment, and append-only-vec. The attacker hijacked a maintainer's account and used a typosquatted crate, proc-macro1, to deliver a malicious build script that downloads and executes a second-stage payload during compilation. The dropper connects to C2 infrastructure hosted on Hostwinds IP addresses, enabling remote code execution without any runtime code changes. The attack leveraged a 'yank-and-upgrade' tactic to lure developers into updating to the malicious version. Six attacker-owned crates were deleted, including a backup dropper (proc-macro-en), and the exposure window lasted from 07:11 to 09:25 UTC on August 20, 2026.