SlowMist Says Rust Supply Chain Attack Hit Three Libraries, Reaching Multiple Solana Components

SlowMist Says Rust Supply Chain Attack Hit Three Libraries, Reaching Multiple Solana Components

N
News Editor
2026-08-21 10:40:30
SlowMist said a Rust supply chain attack affected three legitimate libraries: arrayref@0.3.10, internment@0.8.7 and append-only-vec@0.1.9. The compromised versions introduced a malicious dependency called proc-macro1 that can automatically download and run cross-platform malware during Cargo builds. SlowMist also said arrayref’s older clean release, v0.3.9, had about 152 million downloads, but that usage does not mean any project or host has been compromised. The group advised users to inspect Cargo.lock files, verify resolved versions, rotate exposed credentials if needed, and rebuild affected systems in a trusted environment.

SlowMist said a Rust supply chain attack affected three legitimate libraries: arrayref@0.3.10, internment@0.8.7 and append-only-vec@0.1.9.

According to the group’s monitoring, the compromised versions introduced a malicious dependency called proc-macro1. It can automatically download and execute cross-platform malware during the Cargo build process.

SlowMist said arrayref is widely used across the Rust ecosystem. Its earlier clean version, v0.3.9, had about 152 million downloads. The library also appears indirectly in the dependency chains of several common Rust GUI frameworks, and it has broad coverage in the Solana ecosystem, including token, staking and validator-related components. SlowMist added that those usage figures do not mean the related projects or hosts have been compromised.

The group said attackers could carry out remote code execution during builds, host profiling, persistence, browser data theft, and the execution of other scripts or shell commands.

SlowMist advised users to check Cargo.lock files and build environments for affected versions, use exact version pinning, verify the version actually resolved in Cargo.lock, rotate any potentially exposed credentials, and rebuild affected systems in a trusted environment.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
3700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.