Skip to content

Invest1 publisher3 min readPublished

Rust's arrayref hijack lasted 86 minutes, and Wiz ties it to North Korea

Compiling any project that resolved the poisoned crate on August 20 was enough to run a credential stealer. Wiz links the infrastructure to DPRK-attributed campaigns.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • On August 20, attackers published malicious versions of three widely used Rust crates, led by arrayref.
  • Wiz says the infrastructure used in the arrayref supply chain attack overlaps with North Korean campaigns previously attributed by Microsoft and Mandiant.
  • Because the payload runs during cargo build, the Rust team and Wiz advise treating any workstation or CI runner that resolved a bad version as compromised.
  • Aikido security researcher Ilyas Makari found that the actual code inside arrayref, internment and append-only-vec was not altered; the only change was one new dependency added to each package's list, called proc-macro1.
  • proc-macro1 is a misspelling of the popular proc-macro2 crate, which has over 154 million downloads.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

On August 20, attackers published malicious versions of three widely used Rust crates, led by arrayref [1], and Wiz says the infrastructure behind the operation overlaps with North Korean campaigns previously attributed by Microsoft and Mandiant [2]. The consequence for operators is narrow and unpleasant: because the payload ran during compilation, any workstation or CI runner that resolved a bad version should be treated as compromised, per the Rust team and Wiz [3].

The tradecraft is the interesting part. Ilyas Makari of Aikido found that the code inside arrayref, internment and append-only-vec was not altered at all; the single change was a new dependency in each manifest called proc-macro1 [4]. That name is a misspelling of proc-macro2, a crate with over 154 million downloads [5], and the fake package bundled the real proc-macro2 source, so projects still built and tests still passed [6]. The malicious code sat in the build script, and Cargo runs build scripts automatically at compile time, which the Rust Security Response Team's advisory said was enough on its own to trigger the attack [7]. The second stage stole saved passwords from Chrome, Brave and Edge and installed persistence on Windows, macOS and Linux [8].

Scale explains why this is being taken seriously rather than filed as a curiosity. Wiz describes arrayref as present in roughly three-quarters of environments running Rust [9], and Aikido calls this the biggest Rust crate compromise it has seen by download count, with arrayref at about 244 million total downloads and use in Solana and Ethereum tooling [10]. The exposure was reportedly live for 86 minutes before deletion [11]. That window is short enough that most teams will find nothing, and long enough that the ones who do find something will be the ones building on a schedule. Nextron Systems filed the initial report [12]. The affected releases were arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9, all since deleted from crates.io [13]; the Rust team unyanked the clean versions and locked the maintainer's account [14], and said it does not believe the author acted maliciously, assessing instead that their machine or credentials were compromised [15].

The attribution rests on reuse. Wiz researchers Rami McCarthy and Benjamin Read report that the arrayref payload beacons to a command-and-control path, /49890878, that also appears in the Mastra campaign [16], which Microsoft links to a North Korean group it calls Sapphire Sleet [17]. The IP used in the arrayref attack shares a security certificate with another address used in Mastra [18], a victim flagged an IP that Google Cloud had seen in the axios npm attack [19], and Mandiant attributes that activity to a North Korean group it calls UNC1069, with both attacks using the same host, Hostwinds [20]. This is not the first registry in the pattern: Amazon disclosed on July 29 that it had linked a string of npm library compromises to a single DPRK-linked actor [21].

The motive is financial. TRM Labs reported that North Korean groups accounted for about 76% of all crypto hack value in 2026 through April, roughly $577 million [22], which implies a total pool near $759 million [23]. Black Hat researcher Vangelis Stykas says he tracked North Korean hackers into 1,640 companies across 57 countries, often baiting developers with fake job offers that install malware [24].

Watch whether registries move from yanking bad versions to gating new transitive dependencies added by an existing maintainer, since that manifest line was the only signal here [4].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories