Rust Crates Compromised via Malicious proc-macro1 Dependency
Score: 10/10

Rust Crates Compromised via Malicious proc-macro1 Dependency

Sapphire Sleet (DPRK) compromised popular Rust crates including arrayref and append-only-vec by injecting a malicious typosquatted dependency, proc-macro1, to execute a second-stage backdoor at build time.

Executive Summary

On August 20, 2026, a major supply-chain attack targeted the Rust ecosystem, specifically affecting widely used crates like arrayref (244M+ downloads). Attackers compromised maintainer credentials to inject a malicious dependency, proc-macro1, which mimics the legitimate proc-macro2 package. The attack is highly effective because it triggers a malicious payload execution immediately during the 'cargo build' process, regardless of whether the library functions are actually called.

Attribution points to North Korean threat actors (Sapphire Sleet/UNC1069) due to significant infrastructure and C2 endpoint overlaps with previous Mastra and axios campaigns. The second-stage payload is a sophisticated Rust-based RAT (Remote Access Trojan) capable of host reconnaissance, stealing browser extension data (wallets), and establishing persistent remote shell access across Linux, Windows, and macOS platforms.

Organizations using Rust in their development pipelines or CI/CD environments are at high risk. Any machine that built an affected project during the 86-minute exposure window must be treated as fully compromised, necessitating a full credential rotation and thorough forensic cleanup.

Key Details

Threat Name

Rust proc-macro1 Typosquatting Campaign

Affects

—

Adversary

Sapphire Sleet Other Adversaries and Aliases: UNC1069

Malware/Tools

proc-macro1, proc-macro-en, Mastra, rust-crate_0.1.0, aovine, arone, aronenao, tinymember, botking

Report Score

10out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance10
Enterprise Relevance10
Clarity & Structure9
Technical Depth9

Sources