{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/proc-macro1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["arrayref (0.3.10)","internment (0.8.7)","append-only-vec (0.1.9)","proc-macro1"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eOn August 20, 2026, researchers identified a sophisticated supply chain attack targeting the Rust ecosystem. Attackers compromised maintainer credentials to publish malicious versions of three widely used crates: arrayref (0.3.10), internment (0.8.7), and append-only-vec (0.1.9). These crates were modified to include a dependency on 'proc-macro1', a typosquatted version of the legitimate 'proc-macro2' crate.\u003c/p\u003e\n\u003cp\u003eThe attack leverages the fact that Cargo build scripts are executed with user privileges at compile time. By embedding malicious logic within the build.rs file of the typosquatted crate, the attackers achieve remote code execution whenever an affected project is built. The second-stage payload is a feature-rich backdoor capable of host reconnaissance, browser credential theft, and persistent access. Infrastructure analysis reveals significant overlap with prior supply chain campaigns attributed to North Korean state-sponsored actors, specifically the Mastra and axios campaigns, utilizing Hostwinds LLC infrastructure. Given the ubiquity of these crates, any workstation or CI/CD runner that has built an affected version should be treated as compromised.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker compromises crates.io maintainer credentials or workstation to gain publication access.\u003c/li\u003e\n\u003cli\u003eAttacker publishes malicious versions of arrayref, internment, and append-only-vec, injecting a dependency on the typosquatted 'proc-macro1' crate.\u003c/li\u003e\n\u003cli\u003eVictim project builds a dependency tree including the malicious 'proc-macro1' crate.\u003c/li\u003e\n\u003cli\u003eCargo triggers the malicious 'build.rs' script within 'proc-macro1' during the compilation phase.\u003c/li\u003e\n\u003cli\u003eBuild script reconstructs the C2 URL from Base64 fragments and downloads a platform-specific binary payload (e.g., Linux, Windows, or macOS).\u003c/li\u003e\n\u003cli\u003eThe payload is written to a temporary directory (/tmp/rust-setup or %TEMP%\\rust-setup.ps1) and executed in the background.\u003c/li\u003e\n\u003cli\u003eThe backdoor establishes persistence via systemd services, Registry Run keys, or LaunchAgents.\u003c/li\u003e\n\u003cli\u003eThe backdoor exfiltrates host metadata and stolen browser credentials to the C2 server using HTTPS POST requests.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign affects any developer workstation or automated CI/CD environment that compiled the compromised crates. Successful execution results in full system access, persistent backdoor deployment, and the exfiltration of credentials stored in Chrome, Brave, and Edge browsers. As arrayref is present in a significant percentage of Rust environments, the potential exposure for enterprise build pipelines is substantial, necessitating a full credential rotation and forensic review of affected infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePerform an immediate search for the compromised crate versions (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9) in all 'Cargo.lock' files and local registry caches.\u003c/li\u003e\n\u003cli\u003eTreat all hosts that have compiled these crates as compromised; rotate all credentials, signing keys, and CI secrets accessible from those machines.\u003c/li\u003e\n\u003cli\u003eDelete malicious artifacts including '/tmp/rust-setup', '%TEMP%\\rust-setup.ps1', and '%TEMP%\\rust-setup-launch.vbs'.\u003c/li\u003e\n\u003cli\u003eBlock the C2 IP addresses (23.254.165.112 and 23.254.167.107) and the domain 'hwsrv-798836.hostwindsdns.com' at the network perimeter.\u003c/li\u003e\n\u003cli\u003eReview all new or modified 'build-dependencies' entries in 'Cargo.toml' files, specifically flagging crates that perform unexpected network activity.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-20T19:09:48Z","date_published":"2026-08-20T19:09:48Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rust-supply-chain/","summary":"Threat actors associated with DPRK campaigns compromised the Rust crates.io registry by injecting malicious build scripts into typosquatted dependencies to execute a backdoor on developer and build environments.","title":"Supply Chain Attack Targeting Rust Ecosystem via Malicious Crate Dependencies","url":"https://feed.craftedsignal.io/briefs/2026-08-rust-supply-chain/"}],"language":"en","title":"CraftedSignal Threat Feed - Proc-Macro1","version":"https://jsonfeed.org/version/1.1"}