Supply-chain poisoning hits Rust and npm: build-script backdoors in under two hours
Two supply-chain campaigns surfaced within days of each other, and both followed the same playbook: leave the legitimate code untouched, hide the weapon in the machinery around it, and rely on developers' habit of trusting their dependency tree. First, a compromised crates.io maintainer account published poisoned versions of three widely used Rust crates. Then researchers found fourteen npm packages that worked perfectly while installing a Linux backdoor with an AI-driven control layer.
The crates.io compromise: three crates, one stolen account
On August 20, 2026, malicious releases appeared on crates.io for arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9, all published from the account of a long-standing maintainer who was almost certainly not the author. The Rust Security Response Team locked the account after concluding that the developer's machine or publishing credentials had been compromised. Each malicious version stayed online only briefly before removal: arrayref for about 86 minutes, internment for 90, and append-only-vec for 107 (The Hacker News). A narrow window, but arrayref counts roughly 245 million lifetime downloads, so anyone compiling during that window ran the payload. How the build-script attack actually works
The clever part is that not one line inside arrayref itself was changed. The poisoned release added exactly one new dependency: proc-macro1, a typosquat impersonating David Tolnay's ubiquitous proc-macro2. Its source was a genuine copy of proc-macro2, so every build succeeded and every test passed. The weapon lived solely in its build.rs, a script Cargo executes automatically during compilation. That script reassembled a server address from base64 fragments, downloaded a second-stage binary matched to the host operating system, and launched it detached from the build process. On Unix it wrote to /tmp/rust-setup and marked it executable; on Windows it used a hidden VBScript launcher. Compiling was the trigger, nothing needed to be called (Bleeping Computer). Delivery was engineered too. In the same minute the malicious version went live, the attacker yanked all recent clean releases of arrayref, so Cargo's own "consider updating to a version that is not yanked" warning herded users toward the poisoned release. Security researchers at Wiz noted it was the first dependency ever added to arrayref in its ten-year history, and that infrastructure overlapped with prior DPRK-linked supply-chain campaigns (Wiz). The npm wave: functional utilities hiding RedC2 4.0
Days later, Trend Micro's TrendAI team documented fourteen trojanized npm packages with names like streak-map-kit and streak-calc-math. They genuinely implement the calendar and streak utilities they advertise, but the entry file, dist/index.mjs, also locates a bundled native binary disguised as a math accelerator under names such as math-core.bin, marks it executable, and starts it as a background process. No install hook or function call is needed: a single import anywhere in the dependency graph detonates the payload. The dropped implant is RedShell, the Linux beacon of the RedC2 4.0 command-and-control framework, supporting shell access, file transfer, SSH key theft, SOCKS5 proxying and host-to-host tunneling (The Hacker News). What makes RedC2 notable is its AI layer. A component called Red Agent uses a large language model to turn natural-language prompts into sequences of beacon commands, letting low-skill operators run network reconnaissance and credential dumping conversationally. AI did not create the attack, but it lowers the barrier to running one well. Why pinning and lockfiles matter
Both campaigns exploit the gap between "my code is safe" and "everything my code pulls in is safe". A committed lockfile is your defense: it freezes exact versions and checksums so an unexpected release cannot silently enter your tree. Anyone who resolved dependencies between roughly 07:15 and 09:25 UTC on August 20 could have pulled a poisoned crate without noticing. Auditing means grepping lockfiles for the affected names and versions, not hoping CI logs will confess. The Rust team's guidance is to pin arrayref at 0.3.9 or earlier, since no patched release exists (Rust Blog). Treat any unfamiliar near-namesake dependency, like proc-macro1 instead of proc-macro2, as hostile until proven otherwise. Verifying artifact hashes against independent sources is the same discipline; our sha-256 checksum tool handles the hashing side. Why this matters if you compile anonymity tooling
Users of Tor, Tails-adjacent tooling and privacy software compile from source more than most people, often on machines holding the keys to their entire operational security. An infostealer on such a box defeats every onion address and PGP fingerprint you have carefully verified. The lesson from both incidents is uncomfortable: the malicious code never looked suspicious. It was fast, quiet, and gone from the registry within hours, but the machines it touched stay compromised until you find them. Pin your dependencies, read what a new dependency actually adds before updating, and treat "it compiled successfully" as evidence of nothing at all.