arrayref crates.io compile-time backdoor
campaign · campaign:rust-crates-arrayref-dprk-overlap-2026-08
2026-08-20 crates.io account-takeover compromise of the arrayref, internment and append-only-vec Rust crates via a typosquat build-dependency impersonating proc-macro2, whose build script executed a backdoor at compile time; exposure windows of 86 to 107 minutes per crate. Discovered and reported by Nextron Systems. Wiz Research assesses the infrastructure substantially overlaps operations attributed to North Korean actors (Wiz Research; The Rust Project, 2026-08-20).
Coverage
1
first 2026-08-23 → last 2026-08-23
Latest activity
2026-08-23
Build scripts execute before the crate's own code, so `cargo build` was the whole exploit; Wiz ties the…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, finance, telco · regions: europe
Sources cited
4
4 hosts
Action items (2)
Do-now tasks recorded on the entries about arrayref crates.io compile-time backdoor, newest first. Check the date before acting on an older one.
- Search build and CI logs for any2026-08-23Build scripts execute before the crate's own code…
cargo buildbetween 07:15 and 09:26 UTC on 2026-08-20 that resolved arrayref 0.3.10, internment 0.8.7 or append-only-vec 0.1.9, and treat every workstation and runner that did as compromised rather than merely as needing a dependency bump; the payload ran at compile time and persistence outlives the rollback. - Check2026-08-23Build scripts execute before the crate's own code…
~/.cargo/registry/cacheon developer and build hosts for cached copies of the withdrawn versions; deletion from crates.io does not clear a local cache, and a cached copy will still build.
Defender insights
What each entry about arrayref crates.io compile-time backdoor tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
overlaps with
- Mastra easy-day-js backdoorshared beacon endpoint pattern, TLS certificate issuer and hosting range
- Sapphire SleetWiz reports a shared beacon endpoint with the Mastra campaign Microsoft attributes to Sapphire Sleet at high confidence, a shared TLS certificate issuer, and an address appearing in Google GTIG analysis of the axios compromise attributed to UNC1069, a registered alias of the same cluster. Carried as Wiz's overlap observation, not as attribution.
Story timeline
Hunting pivots
ATT&CK techniques (7 across 6 tactics)
7 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessSupply Chain Compromise: Compromise Software Supply Chain
- PersistenceCreate or Modify System Process: Launch Agent · Create or Modify System Process: Systemd Service · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- Privilege EscalationCreate or Modify System Process: Launch Agent · Create or Modify System Process: Systemd Service · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- StealthDeobfuscate/Decode Files or Information
- DiscoveryBrowser Information Discovery
- Command and ControlDynamic Resolution: Domain Generation Algorithms
Initial Access TA0001
T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗
Persistence TA0003
T1543.001Create or Modify System Process: Launch Agent×1
Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.
Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗
T1543.002Create or Modify System Process: Systemd Service×1
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗
Privilege Escalation TA0004
T1543.001Create or Modify System Process: Launch Agent×1
Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.
Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗
T1543.002Create or Modify System Process: Systemd Service×1
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗
Stealth TA0005
T1140Deobfuscate/Decode Files or Information×1
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.
Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗
Discovery TA0007
T1217Browser Information Discovery×1
Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.
Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗
Command and Control TA0011
T1568.002Dynamic Resolution: Domain Generation Algorithms×1
Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or domains. This has the advantage of making it much harder for defenders to block, track, or take over the command and control channel, as there potentially could be thousands of domains that malware can check for instructions.
Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗
Entries about arrayref crates.io compile-time backdoor (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- append-only-vec (Rust crate)×1
- arrayref (Rust crate)×1
- internment (Rust crate)×1
- Mastra easy-day-js backdoor×1
- Sapphire Sleet×1
Where this entity is cited
Source distribution
- blog.rust-lang.org1 (25%)
- cloud.google.com1 (25%)
- microsoft.com1 (25%)
- wiz.io1 (25%)
All cited sources (4)
- blog.rust-lang.orgThe Rust Project (Rust Security Response Team)https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
- cloud.google.comGoogle Threat Intelligence Grouphttps://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package
- microsoft.comMicrosoft Security Bloghttps://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/
- wiz.ioWiz Researchhttps://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns