MAL-2026-14336Malicious code in arrayref (crates.io)
| Ecosystem | Package | Version |
|---|---|---|
| crates.io | arrayref | 0.3.10 |
{"modified":"2026-08-20T00:00:00Z","published":"2026-08-20T00:00:00Z","schema_version":"1.7.4","id":"MAL-2026-14336","summary":"Malicious code in arrayref (crates.io)","details":"arrayref 0.3.10 was published to crates.io from a maintainer account (droundy) that appears to be compromised. Unlike every prior release, 0.3.10 declares a dependency on the malicious crate proc-macro1. The arrayref source itself is unchanged genuine macro code, but Cargo compiles the declared dependency, so building any project that resolves arrayref 0.3.10 pulls in and builds proc-macro1, whose build script downloads and executes an architecture-specific remote binary at build time from https://23.254.165.112:9089/ and passes 23.254.165.112:443 as a command-and-control address. Part of a coordinated crates.io campaign on 2026-08-20 that also trojanized internment and append-only-vec. The malicious release has been removed from crates.io; releases 0.3.9 and earlier are unaffected.","affected":[{"package":{"ecosystem":"crates.io","name":"arrayref"},"versions":["0.3.10"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"references":[{"type":"REPORT","url":"https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/"},{"type":"WEB","url":"https://github.com/rustsec/advisory-db/issues/3161"}],"credits":[{"name":"SafeDep","type":"FINDER","contact":["https://safedep.io"]},{"name":"jhobern","type":"REPORTER","contact":["https://github.com/jhobern"]}],"database_specific":{"iocs":{"files":[{"note":"Unix second-stage binary, executed with 23.254.165.112:443 as argv[1]","paths":["/tmp/rust-setup"],"source":"DROPPED"},{"note":"Windows PowerShell second-stage","paths":["%TEMP%\\rust-setup.ps1"],"source":"DROPPED"},{"note":"Windows VBScript launcher for the PowerShell stage","paths":["%TEMP%\\rust-setup-launch.vbs"],"source":"DROPPED"}],"ips":["23.254.165.112"],"urls":["https://23.254.165.112:9089/rust-crate_0.1.0","https://23.254.165.112:9089/rust-crate_0.2.0","https://23.254.165.112:9089/rust-crate_0.3.0","https://23.254.165.112:9089/rust-crate_0.4.0"]}}}数据来源:OpenSSF Malicious Packages · Apache-2.0