Malicious Rust Crates Deliver Cross-Platform Backdoor During Builds

Summary
A supply-chain attack compromised three Rust crates, adding a typosquatted dependency that ran malware during Cargo builds. The backdoor targeted Linux, macOS and Windows; Rust removed the releases, and affected build hosts should be treated as compromised.
Key points
- Malicious versions of arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9 added proc-macro1, a typosquat of proc-macro2.
- Cargo automatically ran proc-macro1's build script during compilation, enabling malware execution without the application importing or calling the dependency.
- The loader downloaded platform-specific payloads from 23[.]254[.]165[.]112. The backdoor supported persistence and remote commands across Linux, macOS, and Windows.
- Payloads profiled infected hosts and collected browser login origins, usernames, and extension identifiers; the analyzed stage did not decrypt saved passwords.
- Developer machines and CI/CD systems that built the affected versions may be exposed, including credentials and secrets available to those environments.
- Rust removed the malicious releases and locked the maintainer account as a precaution; the team suspects the maintainer's computer or publishing credentials were compromised.
- Organizations should check dependency records and build artifacts, remove or pin affected versions, investigate for malware and persistence, rotate accessible secrets, and rebuild from a clean system.
Article Details
- Attack Vectors
- A threat actor published malicious versions of three legitimate Rust crates by adding a dependency on the attacker-controlled proc-macro1 crate, a typosquat of proc-macro2.
- Cargo automatically executed proc-macro1's malicious build.rs during compilation; applications did not need to import or call malicious functionality.
- The loader downloaded and executed an OS-specific payload from 23[.]254[.]165[.]112:9089 and passed 23[.]254[.]165[.]112:443 to it as a C2 endpoint.
- The recovered backdoor payloads profiled hosts, inventoried Chromium-based browser data, established user-level persistence, and accepted commands to download and execute scripts or shell commands.
- The backdoor could fall back to deterministic, date-based .com domains if its primary C2 was unavailable.
- Defensive Notes
- The Rust Security Response Team removed the affected releases and locked the maintainer account as a precaution. It suspected compromise of the maintainer's computer or crates.io publishing credentials, rather than malicious action by the maintainer.
- Search Cargo.lock files, dependency inventories, build logs, and Cargo caches for the affected releases and threat actor-controlled crates listed in the article.
- Pin affected legitimate crates to arrayref <= 0.3.9, internment <= 0.8.6, and append-only-vec <= 0.1.8.
- Treat systems that built a malicious version as potentially compromised. Hunt for connections to 23[.]254[.]165[.]112 on ports 9089 and 443, the listed host artifacts, user-level persistence, and suspicious wscript.exe or PowerShell execution associated with Cargo builds.
- Rotate credentials and secrets accessible to affected build environments, and rebuild affected software from a known-clean system.
- The listed DGA domains are hunting indicators; the source says they are not necessarily registered or active. Download counts do not represent compromised hosts.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | abecorkups[.]com | Predicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active. |
| DOMAIN | ackeotawtl[.]com | Predicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active. |
| DOMAIN | epodiatmam[.]com | Predicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active. |
| DOMAIN | fevvkiieiu[.]com | Predicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active. |
| DOMAIN | gafwvcmaja[.]com | Predicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active. |
| DOMAIN | pfhlvoqeeg[.]com | Predicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active. |
| DOMAIN | phrpjtnckf[.]com | Predicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active. |
| DOMAIN | prokxlgfjw[.]com | Predicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active. |
| DOMAIN | rasgthaufd[.]com | Predicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active. |
| DOMAIN | rnssddnegk[.]com | Predicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active. |
| IPV4 | 23[.]254[.]165[.]112 | Attacker-used server for payload downloads on port 9089 and C2 on port 443. |
| SHA256 | 408ef22050ffc5a67e005802809026b29f297a8019f8fda91a2afa8e877ba434 | Linux x86-64 stage-2 payload hash. |
| SHA256 | 492f2ab86f8d8911adc79c10ec1541704f5311d207d9d799b0d2a57fcc6a4391 | Windows x86-64 stage-2 payload hash. |
| SHA256 | 74d3447e7cf99c99ea01a16332ec27432dfb0f491e10e67cd118065a60483306 | macOS ARM64 stage-2 payload hash. |
| SHA256 | c9561a3b00a0fa38b7772675d987f84bd429c55cd024fc08a98245c2d1632848 | macOS x86-64 stage-2 payload hash. |
| SHA256 | cb7778eb6dda91028abf087eb7c3553f981a67e756769507d348e8c201805568 | Malicious build.rs loader shared by proc-macro1@1.0.107 and proc-macro-en@1.0.10. |
| URL | hxxps[:]//23[.]254[.]165[.]112:9089/rust-crate_0[.]1[.]0 | Linux x86-64 stage-2 payload download URL. |
| URL | hxxps[:]//23[.]254[.]165[.]112:9089/rust-crate_0[.]2[.]0 | Windows x86-64 stage-2 payload download URL. |
| URL | hxxps[:]//23[.]254[.]165[.]112:9089/rust-crate_0[.]3[.]0 | macOS x86-64 stage-2 payload download URL. |
| URL | hxxps[:]//23[.]254[.]165[.]112:9089/rust-crate_0[.]4[.]0 | macOS ARM64 stage-2 payload download URL. |
| URL | hxxps[:]//23[.]254[.]165[.]112/49890878 | Stage-2 backdoor C2 beacon URL. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe loader reconstructed Base64-obfuscated C2 addresses.T1033 · System Owner/User DiscoveryThe backdoor collected the host username during profiling.T1059.001 · PowerShellOn Windows, a VBS launcher started hidden PowerShell with ExecutionPolicy Bypass to run the payload.T1082 · System Information DiscoveryThe backdoor profiled the host's OS, architecture, privilege level, and installed applications.T1105 · Ingress Tool TransferThe build script downloaded a platform-specific stage-2 payload from the attacker-used server.T1195.001 · Compromise Software Dependencies and Development ToolsMalicious versions of legitimate Rust crates added the attacker-controlled proc-macro1 dependency, whose build script executed during Cargo builds.T1217 · Browser Information DiscoveryThe backdoor inventoried Chromium-based browsers and collected visited login origins, usernames, and installed extension identifiers.T1543.001 · Launch AgentThe macOS backdoor established persistence through a LaunchAgent.T1543.002 · Systemd ServiceThe Linux backdoor established persistence through a systemd user service.T1547.001 · Registry Run Keys / Startup FolderThe Windows backdoor established persistence through an HKCU Run key.T1568.002 · Domain Generation AlgorithmsThe backdoor generated deterministic, date-based .com domains as fallback C2 destinations.
People
Malware
proc-macro-enproc-macro-en@1.0.10 contained the same malicious build.rs as proc-macro1@1.0.107, while Socket’s analysis of aovine, arone, and aronenao found benign or test-like build scripts consistent with staging activity.proc-macro1A threat actor compromised legitimate Rust crates and injected a malicious proc-macro1 dependency that executed cross-platform malware automatically during Cargo builds.
Vendors
Products
CargoA threat actor compromised legitimate Rust crates and injected a malicious proc-macro1 dependency that executed cross-platform malware automatically during Cargo builds.crates.ionot believe the legitimate maintainer acted maliciously and suspects that the maintainer’s computer or crates.io publishing credentials were compromised, allowing the threat actor to publish malicious versions ofRustA threat actor compromised legitimate Rust crates and injected a malicious proc-macro1 dependency that executed cross-platform malware automatically during Cargo builds.