ixsoftum
Infrastructure

Poisoned Rust crates turned routine cargo builds into malware installers

Published 21 Aug 2026, 16:45 UTC
James Whitaker
James WhitakerStaff writer
Share
Poisoned Rust crates turned routine cargo builds into malware installers

Attackers compromised three widely used Rust crates this week by publishing malicious new versions that turned a normal cargo build into a malware delivery step, according to a report from security firm Nextron Systems. The poisoned releases, arrayref 0.3.10 (245 million lifetime downloads), internment 0.8.7, and append-only-vec 0.1.9 (4 million-plus downloads), each added a dependency on proc-macro1, a typosquat of a legitimate crate carrying the real malicious code.

The build.rs script bundled in proc-macro1 ran during compilation, fingerprinted the developer's OS and CPU architecture, then downloaded and executed a matching payload for Linux, Windows, Intel Macs, or Apple Silicon. The payload targeted Chromium-based browser profiles (Chrome, Brave, Edge) and cryptocurrency wallet extensions, and included persistence and command-and-control capability. Five more packages tied to the same campaign, proc-macro-en, aovine, arone, aronenao, and tinymember, were also flagged as malicious.

The poisoned crates stayed live on the registry for 86 to 107 minutes before the Rust Security Response Team pulled them and locked the compromised maintainer's account, after Nextron reported the campaign on Thursday. Neither Nextron nor the Rust team has disclosed how many developers pulled a poisoned version or how many build machines ran the payload.

For a small team without a dedicated security function, the practical takeaway is that a crate update landing in a Cargo.lock diff deserves the same scrutiny as any other dependency bump, especially one that pulls in an unfamiliar transitive dependency like proc-macro1. Review new transitive dependencies before merging a lockfile update rather than trusting a patch-version bump by default.