Malicious Rust packages were live for 86 minutes, affecting tools used across Solana and Ethereum

Malicious Rust packages were live for 86 minutes, affecting tools used across Solana and Ethereum

N
News Editor
2026-08-21 02:54:54
Attackers pushed malicious versions of three widely used Rust packages in a supply-chain attack, according to Cryptopolitan. One of the compromised libraries, arrayref, is used by roughly three-quarters of Rust development environments. The malicious update concealed a backdoor that could automatically steal login credentials when users compiled projects, potentially exposing both machines and keys for anyone who built affected versions. Wiz researchers said the command-and-control path tied to the arrayref attack overlapped with infrastructure linked to the Mastra campaign used by North Korean hacking group Sapphire Sleet and UNC1069. The IP addresses shared the same security certificate and used the same hosting provider, Hostwinds. The attacker did not alter the original codebase. Instead, they added a typo-squatted dependency, proc-macro1, designed to resemble the popular proc-macro2, allowing the package to pass tests and builds. The malicious release was removed 86 minutes after publication, but it had already been widely downloaded. The affected packages are broadly used in Solana and Ethereum tooling, and the Rust team believes the maintainers were not acting maliciously, with their devices or credentials possibly compromised.

Attackers published malicious versions of three widely used Rust packages in a supply-chain attack, according to Cryptopolitan. One of them, arrayref, is used by roughly three-quarters of Rust development environments.

The malicious update hid a backdoor that could automatically steal login credentials when users compiled their projects. Users who built affected versions may have exposed both their machines and their keys.

A typo-squatted dependency passed tests and builds

Wiz researchers said the command-and-control path in the arrayref attack overlapped with the Mastra campaign used by North Korean hacking group Sapphire Sleet and UNC1069. The IP addresses shared the same security certificate and used the same hosting provider, Hostwinds.

The attacker added only a typo-squatted dependency, proc-macro1, to imitate the popular proc-macro2. The original code was left untouched, which allowed the package to pass tests and builds.

Package was removed after 86 minutes

The malicious release was deleted 86 minutes after it was published, but it had already been downloaded widely. The affected packages are broadly used in Solana and Ethereum tools.

The Rust team said it does not believe the maintainers acted maliciously. Their devices or credentials may have been compromised.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
3300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.