Incident case file
Sign in to watchRust Crates Supply Chain Attack — arrayref, internment, append-only-vec
2 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatAug 20, 2026, 07:11 UTC: The malicious dependency proc-macro1 v1.0.107 is published to crates.io. 07:15 UTC: arrayref@0.3.10 is published, adding the proc-macro1 dependency. 07:34 UTC: internment@0.8.7 is published with the same malicious dependency. 07:37 UTC: append-only-vec@0.1.9 follows. 07:38 UTC: The publication window closes. 08:41 UTC (86 minutes after publication): arrayref@0.3.10 is pulled from crates.io. 09:04 UTC (90 minutes): internment@0.8.7 is pulled. 09:25 UTC (107 minutes): append-only-vec@0.1.9 is pulled, closing the exposure window. Aug 21, 2026 (UTC+8): SlowMist publishes a security disclosure flagging the incident to the broader crypto/Web3 developer community, given arrayref's heavy usage across Solana and other blockchain tooling. Wiz's subsequent analysis links the infrastructure (beacon path, SSL certificate issuer, and hosting provider) to the same cluster behind the earlier 'Mastra' operation, attributed with substantial confidence to the DPRK-linked Sapphire Sleet group, though this remains a firm's threat-intelligence assessment rather than a formally adjudicated attribution. Recommended remediation for affected developers: verify Cargo.lock for the compromised versions, scan the local ~/.cargo/registry/cache, rotate any credentials potentially exposed during the build window, and update to patched crate versions.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)