The arrayref, internment and append-only-vec Supply Chain Attack
Updated 5 Oct 2026 · Incident date 20 Aug 2026 · crates.io
arrayref 0.3.9 -> 0.3.10; internment 0.8.6 -> 0.8.7; append-only-vec 0.1.8 -> 0.1.9Cargo.tomlOn 20 August 2026, attackers published arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9 on crates.io. Each release added a dependency named proc-macro1. That crate downloaded and ran a program from a remote server when the project compiled.
The three crates are common building blocks. JFrog reports about 245 million downloads for arrayref alone. The previous releases (0.3.9, 0.8.6 and 0.1.8) were clean.
What happened
Attackers took over publishing for three popular Rust crates and released one new version of each. The Rust Security Response Team determined that the maintainer's machine or credentials were compromised, as reported by Wiz. The malicious versions went up within minutes of each other at about 07:29 UTC, according to Socket.
The new versions did not hold the malicious code. They added a dependency on proc-macro1. This crate imitates the real proc-macro2 crate and shows a forged author name. It has a build.rs file. Cargo runs a build script during compilation, so the code ran with no import in your source.
The build script rebuilt a server address from Base64 fragments, turned off TLS certificate checks, and detected the operating system. It then downloaded a payload for that system and ran it. The second stage profiled the host, listed Chromium browser logins, set up persistence and waited for remote commands. Wiz reports substantial overlap with North Korean campaigns, such as the same /49890878 beacon path used in an earlier campaign.
This is a clear case of a trusted package that gained a new dependency with a new capability. Vigilance compares the version you trust with the new one. It reports the manifest change, Cargo.toml, as the file that gained the new capability. See the scan block below.
Affected versions
arrayref0.3.10. Last clean version: 0.3.9.internment0.8.7. Last clean version: 0.8.6.append-only-vec0.1.9. Last clean version: 0.1.8.proc-macro11.0.107, the malicious dependency. The attackers deleted this crate, so you will not find it on the registry now.- Other attacker crates named in the reports:
proc-macro-en,aovine,arone,aronenaoandtinymember.
JFrog reports that the last four crates carried no remote payload. Any machine that compiled a project with a bad version on 20 August 2026 or later can be affected.
Indicators of compromise
- Payload host:
23.254.165.112:9089. Command server:23.254.165.112:443. - Download paths:
/rust-crate_0.1.0(Linux x86-64),/rust-crate_0.2.0(Windows),/rust-crate_0.3.0(macOS x86-64),/rust-crate_0.4.0(macOS ARM64). - Beacon path:
/49890878. - Files:
/tmp/rust-setup,%TEMP%\rust-setup.ps1,%TEMP%\rust-setup-launch.vbs. - Persistence: HKCU Run key (Windows), systemd user service (Linux), LaunchAgent (macOS).
- SHA-256 of
arrayref-0.3.10.crate:25ad700976873c76af785cb99b33c48db7df8b81f21d1e9e06b3676b9a9373ae. - SHA-256 of
proc-macro1-1.0.107.crate:61198155da51b838772eecf5bfaac6cbc4dcc388dccc56658fc28a8e831b34d4.
Socket also lists domain-generation domains seen from 20 to 24 August 2026 and a second command address, 23.254.167.107:443. Use the Socket report for the full list.
How to check
Search every Cargo.lock for the bad versions and the malicious crate names. Then look for the dropped files.
grep -rnE "proc-macro1|proc-macro-en|name = \"(arrayref|internment|append-only-vec)\"" --include=Cargo.lock . -A1
Check the version line under each match. Then search for the payload on Linux or macOS.
ls -l /tmp/rust-setup
On Windows, look for %TEMP%\rust-setup.ps1. Search build logs for unexpected PowerShell or wscript.exe runs.
What to do now
- Pin the crates to
arrayref0.3.9,internment0.8.6 andappend-only-vec0.1.8, then regenerate the lockfile. - Remove any
proc-macro1entry fromCargo.lock. - If a bad version compiled on a machine, treat the host as compromised. Wiz and JFrog both give this advice.
- Rotate every credential the build environment can read. Reset passwords stored in browsers.
- Delete the payload files and the persistence entries listed above.
- Block the IP addresses above at the network edge.
- Review new dependencies that run network code at build time before you update.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 16 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED build.rs It now downloads from the internet and runs other programs. It did not before.
Frequently asked questions
Which versions of arrayref were compromised?
Version 0.3.10 of arrayref was malicious. Version 0.3.9 is the last clean release. The same attack hit internment 0.8.7 and append-only-vec 0.1.9.
How does the proc-macro1 crate attack a machine?
It has a build.rs script that Cargo runs during compilation. The script downloads a payload for the local operating system and runs it, with no import needed in your code.
Sources
More supply chain attacks
- onering crate build-script code exfiltration 10 Jun 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.