Abstrakter Code als Symbol fuer eine Sicherheitsluecke

Supply-Chain Attack Poisons Popular Rust Crate arrayref

The Rust security team has reported a supply-chain attack on the popular arrayref crate. Unknown actors injected malicious code via a disguised dependency – the tampered version was online for 86 minutes.

How the attack worked

On 20 August, the attackers created GitHub and crates.io accounts impersonating well-known Rust developer David Tolnay. They republished arrayref and added a dependency on “proc-macro1” – a typosquat of the real crate proc-macro2. A build script then downloaded a malicious payload; according to reports, an infostealer that grabs developer credentials. The rest of the source code was left unchanged to avoid drawing attention.

Scale and response

arrayref has over 53 million downloads in 90 days and is used in cryptography, graphics and blockchain tools. Within just 23 minutes, the attackers also poisoned the crates append-only-vec and internment. The tampered version [email protected] was online for 86 minutes (07:15 to 08:41 UTC), then deleted. The Rust team does not believe the arrayref author is the culprit – their credentials or computer were likely compromised.


Sources: Rust Blog, BleepingComputer.

Mastodon
Scroll to Top