Crypto insigtX

Supply Chain Attack Hits Rust Base Library Arrayref, Suspected to Be North Korean Hackers

According to Cryptopolitan, attackers released malicious versions of three widely used Rust code packages via a supply chain attack, with the library named arrayref used by approximately three-quarters…

Published
Market
Crypto
Source
insigtX

According to Cryptopolitan, attackers released malicious versions of three widely used Rust code packages via a supply chain attack, with the library named arrayref used by approximately three-quarters of Rust development environments. The malicious update hid a backdoor that could automatically steal login information when users compiled projects, and users who compiled affected versions may have exposed their computers and keys. Wiz researchers noted that the command-and-control path of the arrayref attack overlaps with the Mastra operation used by North Korean hacker groups Sapphire Sleet and UNC1069, with IP addresses sharing the same security certificate and using the same hosting provider Hostwinds. The attackers only added a misspelled proc-macro1 dependency, mimicking the popular proc-macro2, without modifying the original code, allowing it to pass tests and builds. The attack was removed 86 minutes after release but had already been widely downloaded. The affected packages are widely used in Solana and Ethereum tools. The Rust team believes the maintainer was not maliciously acting, and their device or credentials may have been compromised.

insigtX content is informational and educational, not investment advice.