logo

Hackers poison arrayref Rust crate to push infostealer malware

ID: 718adfc9-a1c8-59ad-9c74-5888a68831a8

STIX ID: report--718adfc9-a1c8-59ad-9c74-5888a68831a8

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: Bill Toulas

...
...

Attackers compromised a Rust maintainer account to publish malicious releases of popular crates (notably arrayref) that added a typosquatted dependency (proc-macro1) whose build script executed during compilation to deploy a cross-platform infostealer; the malware collects browser credentials, establishes persistence (Windows Registry Run, macOS LaunchAgent, systemd on Linux), and communicates with C2 infrastructure (IOC example: 23.254.165.112 on ports 9089/443).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.