A typosquatted dependency, proc-macro1, used Rust build scripts to fetch and run a second-stage payload, so developers did not need to call any package code for the infection to fire.
Wiz said the payload harvested system and browser data, could persist on Windows, macOS and Linux, and used fallback domain generation if its primary command-and-control infrastructure went down.
StepSecurity said arrayref alone has 245 million lifetime downloads, with the malicious versions exposed for roughly 86 to 107 minutes before deletion.
Wiz linked the infrastructure to recent DPRK-attributed supply-chain campaigns including Mastra and Axios, and urged teams to check Cargo.lock files and treat any machine that built the packages as compromised.