Hackers Poison Arrayref Rust Crate to Push Infostealer Malware
The poisoned releases ran during compilation and stole browser credentials and crypto keys before removal, with arrayref alone drawing more than 245 million downloads.
- Hackers compromised a trusted maintainer account this week, pushing malicious updates to widely used Rust crates including Arrayref and Append-only-vec, infecting developer machines during routine software builds via Cargo.
- Nextron Systems researchers flagged a suspicious crate called proc-macro1, prompting The Rust Security Response Team to disclose the supply chain attack on Thursday after malicious versions sat on the registry for 86, 90, and 107 minutes.
- Security firm Aikido found the malware targeted Chromium-based browsers like Chrome, Brave, and Microsoft Edge to steal credentials and crypto wallet data, while Arrayref's more than 245 million lifetime downloads meant widespread exposure.
- The Rust Security Response Team removed the compromised packages and locked the maintainer account, while urging developers to check their Cargo lockfiles and local registry caches for potential infections.
- Wiz analysts Rami McCarthy and Benjamin Read attributed the infrastructure to Sapphire Sleet, a North Korean state-sponsored group, suggesting adversaries are increasingly weaponizing developer ecosystems to gain access to downstream enterprise networks.
18 Articles
18 Articles
North Korean Hackers Hijack Popular Rust Crates in Hours-Long Supply Chain Strike
Hackers gained control of a trusted maintainer account this week and pushed malicious updates to three widely used Rust crates. The packages ran at build time. They stole credentials from browsers, crypto wallet extensions, and developer environments. The incident lasted barely two hours on crates.io. Yet its reach could stretch across hundreds of millions of downloads and thousands of production systems. The Rust Security Response Team disclose…
Hackers poison popular Rust crates to steal developers' credentials
Hackers slipped malware into several popular Rust packages this week, turning routine software builds into a route onto developers' machines. The Rust Security Response Team disclosed the supply chain attack on Thursday after receiving a tip about a crate called proc-macro1. An investigation found that its build script fetched malware from a remote server. The attack extended beyond a single dodgy crate. Someone had published a new version of ar…
Evidence of involvement by a North Korean-linked hacking group has once again been found in cyber attacks involving software components widely used worldwide.
Hackers Target Popular arrayref Rust Crate in Supply-Chain Attack
Security researchers are sorting through a complex, stealthy, and fast-moving supply-chain attack aimed at pushing information-stealing malware by compromising the account of the maintainer of multiple Rust crates and introducing four more attacker-owned crates. In addition, researchers with Wiz wrote that there also appears to be overlap with supply chain campaigns run by nation-state actors linked to the government of North Korea. According to…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











