{
  "type": "bundle",
  "id": "bundle--bb4ece00-0101-47af-845b-09651bc5075a",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-20T00:00:00.000Z",
      "modified": "2026-08-20T00:00:00.000Z",
      "name": "Optimus Labs · Civilizations",
      "identity_class": "organization",
      "description": "Threat research team at Optimus Labs. Agentic AI attack surface research.",
      "contact_information": "https://www.optimuslabs.io/research/briefings"
    },
    {
      "type": "report",
      "spec_version": "2.1",
      "id": "report--8abe23fc-0101-403b-8744-0ec398bbf543",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-20T00:00:00.000Z",
      "modified": "2026-08-20T00:00:00.000Z",
      "name": "arrayref: a Poisoned Rust Crate Hits the AI Build Endpoint",
      "description": "The DPRK crew behind the Mastra AI-framework attack poisoned arrayref so its build script runs a credential stealer during cargo build, on the developer or CI endpoint that builds your AI tooling, not on your inference nodes.\n\nA compromised maintainer account (droundy), alongside an impersonation account (dtolney, mimicking dtolnay) published malicious arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9 to crates.io. Each added a typosquatted dependency, proc-macro1 (mimicking proc-macro2), whose build.rs downloads and executes a stage-2 implant during compilation. Merely building an affected project, locally, in CI, or through an AI coding agent, executes it. This is not a model backdoor. The payload runs at compile time, so the target is the machine that builds AI tooling and the value to the actor is that host's credential store.",
      "published": "2026-08-20T00:00:00.000Z",
      "report_types": [
        "threat-report"
      ],
      "confidence": 85,
      "labels": [
        "Supply chain",
        "Coding agent",
        "Supply Chain nth Party Risk",
        "AI Asset Supply Chain Security",
        "Agentware Lifecycle Security",
        "Cyber Hygiene",
        "severity:critical"
      ],
      "object_refs": [
        "indicator--703b2f5c-0102-4b1c-8139-8440713dda78",
        "indicator--570ecafc-0102-473f-860c-ddc35810e23b",
        "indicator--a7bf77e5-0102-48a0-8594-290bba8c1908",
        "indicator--e6c5b0cb-0104-4a3b-8183-e0510e7c9fb0",
        "indicator--a3717d98-0102-4d21-85d8-cef47a473eab",
        "software--cce2dcbe-0101-4ba3-8321-cf8e3cde4b86",
        "software--019bd2b0-0101-46cd-809a-647d029d897d",
        "software--089c6a68-0101-4e66-899d-040e099dd8ce",
        "software--06eb64d8-0102-45e1-87e9-413907ed8ab9",
        "software--c86618b0-0101-48f8-8369-85fb8c967d1a"
      ],
      "external_references": [
        {
          "source_name": "Optimus Labs · Civilizations",
          "url": "https://www.optimuslabs.io/research/briefings/arrayref-rust-crate-build-time-rce"
        },
        {
          "source_name": "RUSTSEC-2026-0260 — canonical advisory",
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0260.html"
        },
        {
          "source_name": "StepSecurity — build-time chain analysis",
          "url": "https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack"
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--703b2f5c-0102-4b1c-8139-8440713dda78",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-20T00:00:00.000Z",
      "modified": "2026-08-20T00:00:00.000Z",
      "name": "file: rust-setup.ps1",
      "description": "Files: /tmp/rust-setup, %TEMP%\\rust-setup.ps1, %TEMP%\\rust-setup-launch.vbs",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[file:name = 'rust-setup.ps1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-20T00:00:00.000Z",
      "labels": [
        "arrayref-rust-crate-build-time-rce",
        "supply-chain",
        "coding-agent"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--570ecafc-0102-473f-860c-ddc35810e23b",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-20T00:00:00.000Z",
      "modified": "2026-08-20T00:00:00.000Z",
      "name": "ipv4: 23.254.165.112",
      "description": "Network: 23.254.165[.]112:9089 and :443, 23.254.167[.]107:443, hwsrv-798836.hostwindsdns[.]com",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[ipv4-addr:value = '23.254.165.112']",
      "pattern_type": "stix",
      "valid_from": "2026-08-20T00:00:00.000Z",
      "labels": [
        "arrayref-rust-crate-build-time-rce",
        "supply-chain",
        "coding-agent"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7bf77e5-0102-48a0-8594-290bba8c1908",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-20T00:00:00.000Z",
      "modified": "2026-08-20T00:00:00.000Z",
      "name": "ipv4: 23.254.167.107",
      "description": "Network: 23.254.165[.]112:9089 and :443, 23.254.167[.]107:443, hwsrv-798836.hostwindsdns[.]com",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[ipv4-addr:value = '23.254.167.107']",
      "pattern_type": "stix",
      "valid_from": "2026-08-20T00:00:00.000Z",
      "labels": [
        "arrayref-rust-crate-build-time-rce",
        "supply-chain",
        "coding-agent"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6c5b0cb-0104-4a3b-8183-e0510e7c9fb0",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-20T00:00:00.000Z",
      "modified": "2026-08-20T00:00:00.000Z",
      "name": "domain: hwsrv-798836.hostwindsdns.com",
      "description": "Network: 23.254.165[.]112:9089 and :443, 23.254.167[.]107:443, hwsrv-798836.hostwindsdns[.]com",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hwsrv-798836.hostwindsdns.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-20T00:00:00.000Z",
      "labels": [
        "arrayref-rust-crate-build-time-rce",
        "supply-chain",
        "coding-agent"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3717d98-0102-4d21-85d8-cef47a473eab",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-20T00:00:00.000Z",
      "modified": "2026-08-20T00:00:00.000Z",
      "name": "domain: crates.io",
      "description": "Publishing tokens: crates.io / npm",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'crates.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-20T00:00:00.000Z",
      "labels": [
        "arrayref-rust-crate-build-time-rce",
        "supply-chain",
        "coding-agent"
      ]
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--cce2dcbe-0101-4ba3-8321-cf8e3cde4b86",
      "name": "crates.io"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--019bd2b0-0101-46cd-809a-647d029d897d",
      "name": "RustSec"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--089c6a68-0101-4e66-899d-040e099dd8ce",
      "name": "Wiz"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--06eb64d8-0102-45e1-87e9-413907ed8ab9",
      "name": "StepSecurity"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--c86618b0-0101-48f8-8369-85fb8c967d1a",
      "name": "Semgrep"
    }
  ]
}