Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack
ID: f6cb2e66-1d02-50b2-8ceb-3a676f3f5f13
STIX ID: report--f6cb2e66-1d02-50b2-8ceb-3a676f3f5f13
Feed Name: Aikido Security's Blog
Threat Score
On August 20, attackers typosquatted a widely used Rust dependency (proc-macro1) and injected it as a build-time dependency into two popular crates (append-only-vec and arrayref); the malicious build script downloads and executes platform-specific payloads that act as an infostealer (targeting Chromium-based browsers), establish C2 communication, and implement persistence (macOS LaunchAgent), with IP and file-hash IOCs provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
