logo

Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack

ID: f6cb2e66-1d02-50b2-8ceb-3a676f3f5f13

STIX ID: report--f6cb2e66-1d02-50b2-8ceb-3a676f3f5f13

Feed Name: Aikido Security's Blog

Threat Score
85/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

...
...

On August 20, attackers typosquatted a widely used Rust dependency (proc-macro1) and injected it as a build-time dependency into two popular crates (append-only-vec and arrayref); the malicious build script downloads and executes platform-specific payloads that act as an infostealer (targeting Chromium-based browsers), establish C2 communication, and implement persistence (macOS LaunchAgent), with IP and file-hash IOCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.