Rust Supply Chain Attack Compromises Crates with 245 Million Downloads
A supply chain attack on the Rust programming language has compromised three widely used crates, potentially affecting 245 million downloads. The attack was carried out by a compromised maintainer account, which published malicious versions of the crates.

The Rust Project has removed malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency. This dependency downloaded and executed a remote payload during compilation, potentially compromising projects that used the affected crates.
Affected Crates
The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9. These crates were published from the same owner account on August 20, 2026, and were removed within 86 to 107 minutes.
Malicious Code
The malicious code was added to the build script of the injected dependency, allowing it to download and execute a remote payload during compilation. This means that building a project that resolved the malicious dependency was sufficient to run the payload, without needing to call any functions from the crates themselves.
Indicators of Compromise
The following indicators of compromise (IoCs) have been shared by StepSecurity:
- Network: 23.254.165.112:9089 (payload host), 23.254.165.112:443 (C2), hwsrv-798836.hostwindsdns.com
- Files: /tmp/rust-setup, %TEMP%ust-setup.ps1, %TEMP%ust-setup-launch.vbs
- Binaries: rust-crate_0.1.0, _0.2.0, _0.3.0, _0.4.0
- Accounts: dtolney (crates.io id 438608), impersonator; droundy, legitimate owner, presumed compromised
- Email: rchaitm@gmail.com, forged author metadata
Mitigation and Response
Developers are advised to search for the deleted crate files and to pin arrayref at 0.3.9 or earlier. The Rust Security Response Team has unyanked the maliciously-yanked versions during the response, but there is no patched version and no CVE identifier has been assigned. The team believes that the author of arrayref is not acting maliciously, but their computer or credentials are likely compromised.
The malicious versions of the crates were online for a short period, with the following timeline:
| Crate | Published | Deleted | Online |
|---|---|---|---|
| arrayref@0.3.10 | 2026-08-20T07:15:00Z | 2026-08-20T08:41:40Z | 86 minutes |
| internment@0.8.7 | 2026-08-20T07:34:07Z | 2026-08-20T09:04:11Z | 90 minutes |
| append-only-vec@0.1.9 | 2026-08-20T07:37:49Z | 2026-08-20T09:25:24Z | 107 minutes |
The attack highlights the importance of monitoring dependencies and implementing security measures to prevent similar attacks in the future. Cargo has no shipped equivalent to a cooldown period for newly published dependencies, but a pull request stabilizing a global-min-publish-age setting is currently open.
The infrastructure used in the attack substantially overlaps with recent North Korean supply chain attacks, but no vendor has attributed the crates.io incident to a named actor. The scope of the compromise is estimated to be broad, given the high download count of the affected crates.
In a similar case in September 2025, two malicious crates impersonating a logging library executed only at runtime. The current attack is more severe, as the malicious code is executed during compilation, potentially affecting a wider range of projects.
Developers should be cautious when using dependencies from crates.io and monitor their projects for any signs of compromise. The Rust Security Response Team and other security experts are continuing to investigate the attack and provide guidance on how to mitigate its effects.
The incident highlights the importance of security in the software development process and the need for developers to be aware of the potential risks associated with using dependencies from external sources. By taking steps to monitor and secure their dependencies, developers can reduce the risk of similar attacks in the future.
The attack on the Rust crates is a reminder that software development is a complex process that involves many different components and dependencies. As such, it is essential to have robust security measures in place to prevent and detect potential threats.
In conclusion, the supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development. Developers should be aware of the potential risks associated with using dependencies from external sources and take steps to monitor and secure their projects. By doing so, they can reduce the risk of similar attacks in the future and ensure the integrity of their software.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development.
The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
In the meantime, developers should remain cautious when using dependencies from crates.io and monitor their projects for any signs of compromise. The Rust Security Response Team and other security experts are continuing to investigate the attack and provide guidance on how to mitigate its effects.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
In the end, the supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development. Developers should be aware of the potential risks associated with using dependencies from external sources and take steps to monitor and secure their projects. By doing so, they can reduce the risk of similar attacks in the future and ensure the integrity of their software.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers.
By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process. The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers.
By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers.
By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and developers can contribute to this effort by reporting any suspicious activity and following best practices for secure software development. The incident is a wake-up call for the software development community, and it highlights the importance of security in the development process.
The Rust community is committed to improving the security of the crates.io ecosystem, and developers can contribute to this effort by following best practices for secure software development and reporting any suspicious activity. The incident is a reminder that security is an ongoing process that requires constant vigilance and attention to detail.
By taking a proactive approach to security, developers can help to prevent similar attacks in the future and ensure the integrity of their software. The supply chain attack on the Rust crates is a significant incident that highlights the importance of security in software development, and it is a reminder that developers must be aware of the potential risks associated with using dependencies from external sources.
The incident is a reminder that security is a shared responsibility that requires the cooperation and vigilance of all developers. By working together, developers can create a more secure software development ecosystem and reduce the risk of similar attacks in the future.
The Rust community is working to improve the security of the crates.io ecosystem, and





