Malicious Rust Crates Deliver Cross-Platform Backdoor During Builds

· Original article ↗

Summary

A supply-chain attack compromised three Rust crates, adding a typosquatted dependency that ran malware during Cargo builds. The backdoor targeted Linux, macOS and Windows; Rust removed the releases, and affected build hosts should be treated as compromised.

Key points

  • Malicious versions of arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9 added proc-macro1, a typosquat of proc-macro2.
  • Cargo automatically ran proc-macro1's build script during compilation, enabling malware execution without the application importing or calling the dependency.
  • The loader downloaded platform-specific payloads from 23[.]254[.]165[.]112. The backdoor supported persistence and remote commands across Linux, macOS, and Windows.
  • Payloads profiled infected hosts and collected browser login origins, usernames, and extension identifiers; the analyzed stage did not decrypt saved passwords.
  • Developer machines and CI/CD systems that built the affected versions may be exposed, including credentials and secrets available to those environments.
  • Rust removed the malicious releases and locked the maintainer account as a precaution; the team suspects the maintainer's computer or publishing credentials were compromised.
  • Organizations should check dependency records and build artifacts, remove or pin affected versions, investigate for malware and persistence, rotate accessible secrets, and rebuild from a clean system.

Article Details

Attack Vectors
  • A threat actor published malicious versions of three legitimate Rust crates by adding a dependency on the attacker-controlled proc-macro1 crate, a typosquat of proc-macro2.
  • Cargo automatically executed proc-macro1's malicious build.rs during compilation; applications did not need to import or call malicious functionality.
  • The loader downloaded and executed an OS-specific payload from 23[.]254[.]165[.]112:9089 and passed 23[.]254[.]165[.]112:443 to it as a C2 endpoint.
  • The recovered backdoor payloads profiled hosts, inventoried Chromium-based browser data, established user-level persistence, and accepted commands to download and execute scripts or shell commands.
  • The backdoor could fall back to deterministic, date-based .com domains if its primary C2 was unavailable.
Defensive Notes
  • The Rust Security Response Team removed the affected releases and locked the maintainer account as a precaution. It suspected compromise of the maintainer's computer or crates.io publishing credentials, rather than malicious action by the maintainer.
  • Search Cargo.lock files, dependency inventories, build logs, and Cargo caches for the affected releases and threat actor-controlled crates listed in the article.
  • Pin affected legitimate crates to arrayref <= 0.3.9, internment <= 0.8.6, and append-only-vec <= 0.1.8.
  • Treat systems that built a malicious version as potentially compromised. Hunt for connections to 23[.]254[.]165[.]112 on ports 9089 and 443, the listed host artifacts, user-level persistence, and suspicious wscript.exe or PowerShell execution associated with Cargo builds.
  • Rotate credentials and secrets accessible to affected build environments, and rebuild affected software from a known-clean system.
  • The listed DGA domains are hunting indicators; the source says they are not necessarily registered or active. Download counts do not represent compromised hosts.

Indicators of compromise

TypeIndicatorContext
DOMAINabecorkups[.]comPredicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active.
DOMAINackeotawtl[.]comPredicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active.
DOMAINepodiatmam[.]comPredicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active.
DOMAINfevvkiieiu[.]comPredicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active.
DOMAINgafwvcmaja[.]comPredicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active.
DOMAINpfhlvoqeeg[.]comPredicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active.
DOMAINphrpjtnckf[.]comPredicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active.
DOMAINprokxlgfjw[.]comPredicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active.
DOMAINrasgthaufd[.]comPredicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active.
DOMAINrnssddnegk[.]comPredicted backdoor DGA hunting indicator for August 20–24, 2026; not necessarily registered or active.
IPV423[.]254[.]165[.]112Attacker-used server for payload downloads on port 9089 and C2 on port 443.
SHA256408ef22050ffc5a67e005802809026b29f297a8019f8fda91a2afa8e877ba434Linux x86-64 stage-2 payload hash.
SHA256492f2ab86f8d8911adc79c10ec1541704f5311d207d9d799b0d2a57fcc6a4391Windows x86-64 stage-2 payload hash.
SHA25674d3447e7cf99c99ea01a16332ec27432dfb0f491e10e67cd118065a60483306macOS ARM64 stage-2 payload hash.
SHA256c9561a3b00a0fa38b7772675d987f84bd429c55cd024fc08a98245c2d1632848macOS x86-64 stage-2 payload hash.
SHA256cb7778eb6dda91028abf087eb7c3553f981a67e756769507d348e8c201805568Malicious build.rs loader shared by proc-macro1@1.0.107 and proc-macro-en@1.0.10.
URLhxxps[:]//23[.]254[.]165[.]112:9089/rust-crate_0[.]1[.]0Linux x86-64 stage-2 payload download URL.
URLhxxps[:]//23[.]254[.]165[.]112:9089/rust-crate_0[.]2[.]0Windows x86-64 stage-2 payload download URL.
URLhxxps[:]//23[.]254[.]165[.]112:9089/rust-crate_0[.]3[.]0macOS x86-64 stage-2 payload download URL.
URLhxxps[:]//23[.]254[.]165[.]112:9089/rust-crate_0[.]4[.]0macOS ARM64 stage-2 payload download URL.
URLhxxps[:]//23[.]254[.]165[.]112/49890878Stage-2 backdoor C2 beacon URL.

MITRE ATT&CK

People

Malware

Vendors

Products

Tools

Related Articles