Executive Summary
On August 20, 2026, a major supply-chain attack targeted the Rust ecosystem, specifically affecting widely used crates like arrayref (244M+ downloads). Attackers compromised maintainer credentials to inject a malicious dependency, proc-macro1, which mimics the legitimate proc-macro2 package. The attack is highly effective because it triggers a malicious payload execution immediately during the 'cargo build' process, regardless of whether the library functions are actually called.
Attribution points to North Korean threat actors (Sapphire Sleet/UNC1069) due to significant infrastructure and C2 endpoint overlaps with previous Mastra and axios campaigns. The second-stage payload is a sophisticated Rust-based RAT (Remote Access Trojan) capable of host reconnaissance, stealing browser extension data (wallets), and establishing persistent remote shell access across Linux, Windows, and macOS platforms.
Organizations using Rust in their development pipelines or CI/CD environments are at high risk. Any machine that built an affected project during the 86-minute exposure window must be treated as fully compromised, necessitating a full credential rotation and thorough forensic cleanup.
Key Details
Threat Name
Rust proc-macro1 Typosquatting Campaign
Affects
—
Adversary
Sapphire Sleet Other Adversaries and Aliases: UNC1069
MITRE Techniques
Malware/Tools
proc-macro1, proc-macro-en, Mastra, rust-crate_0.1.0, aovine, arone, aronenao, tinymember, botking
