Researchers Link Arrayref Library Hack in Rust to North Korean Hackers
Researchers link the hack of the Rust 'arrayref' library to North Korean hackers, in a major software supply chain attack. The malicious update, which was live for 86 minutes, added a malicious dependency named 'proc-macro1' to the arrayref, internment, and append-only-vec packages. This typo-squatted on the legitimate 'proc-macro2' crate and concealed a backdoor in the build script. Compiling a project using the compromised version was enough to trigger the attack, which stole saved passwords from browsers like Chrome, Brave, and Edge across Windows, Mac, and Linux systems. With approximately 244 million downloads, this is considered the largest Rust crate compromise by download volume. Security firms Wiz, Mandiant, and others attribute the attack to North Korean groups like Sapphire Sleet (Microsoft) or UNC1069 (Mandiant), citing infrastructure overlaps with other campaigns like Mastra. The Rust Security team removed the packages and blocked the developer account, though they believe the developer's account was compromised rather than acting maliciously. The incident underscores North Korea's continued focus on cryptocurrency theft and software supply chain attacks.
cryptonews.ruHá 50m