Hackers poison arrayref Rust crate to push infostealer malware
ID: 718adfc9-a1c8-59ad-9c74-5888a68831a8
STIX ID: report--718adfc9-a1c8-59ad-9c74-5888a68831a8
Feed Name: Bleeping Computer
Threat Score
Attackers compromised a Rust maintainer account to publish malicious releases of popular crates (notably arrayref) that added a typosquatted dependency (proc-macro1) whose build script executed during compilation to deploy a cross-platform infostealer; the malware collects browser credentials, establishes persistence (Windows Registry Run, macOS LaunchAgent, systemd on Linux), and communicates with C2 infrastructure (IOC example: 23.254.165.112 on ports 9089/443).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
