Malicious arrayref 0.3.10 was downloaded 2,285 times from crates.io in the 86 minutes before Rust's security response team deleted it on August 20. Lockfiles still pinned to 0.3.9 kept most builds away from its unsandboxed build-script payload.
Reality
- Evidence62
- Adoption18
- Hype gap+8
- Incentives
- Insufficient
- Confidence60
Malicious versions of three Rust crates ran code at compile time on August 20. Wiz says the infrastructure overlaps with DPRK operations, so the campaign should be treated as live.
Perspective Coverage
6 publishers
- Builder
- Builder 45%
- Operator
- Operator 48%
- Investor
- Investor 7%
Reality
- Evidence80
- Adoption30
- Hype gap+25
- Incentives55
- Confidence75
The Rust Security Response Team deleted proc-macro1 and arrayref 0.3.10 on August 20 after a build script fetched and launched a binary. The lure was a yank warning.
Publishers:blog.rust-lang.org · dev.to · lwn.net · research.jfrog.com · runtimewire.com · rustsec.org · socket.dev Perspective Coverage
7 publishers
- Builder
- Builder 38%
- Operator
- Operator 54%
- Investor
- Investor 8%
Reality
- Evidence86
- Adoption15
- Hype gap+35
- Incentives60
- Confidence82
Wiz says a compile-time payload reached builds through a typosquatted dependency, and the attacker yanked every clean arrayref release so the responsible fix resolved to the poisoned one.
Reality
- Evidence66
- Adoption74
- Hype gap+12
- Incentives62
- Confidence58
Compiling any project that resolved the poisoned crate on August 20 was enough to run a credential stealer. Wiz links the infrastructure to DPRK-attributed campaigns.
Reality
- Evidence48
- Adoption61
- Hype gap+17
- Incentives63
- Confidence52