Researchers Link Arrayref Library Hack in Rust to North Korean Hackers

cryptonews.ruPublicado em 2026-08-20Última atualização em 2026-08-20

Resumo

Researchers link the hack of the Rust 'arrayref' library to North Korean hackers, in a major software supply chain attack. The malicious update, which was live for 86 minutes, added a malicious dependency named 'proc-macro1' to the arrayref, internment, and append-only-vec packages. This typo-squatted on the legitimate 'proc-macro2' crate and concealed a backdoor in the build script. Compiling a project using the compromised version was enough to trigger the attack, which stole saved passwords from browsers like Chrome, Brave, and Edge across Windows, Mac, and Linux systems. With approximately 244 million downloads, this is considered the largest Rust crate compromise by download volume. Security firms Wiz, Mandiant, and others attribute the attack to North Korean groups like Sapphire Sleet (Microsoft) or UNC1069 (Mandiant), citing infrastructure overlaps with other campaigns like Mastra. The Rust Security team removed the packages and blocked the developer account, though they believe the developer's account was compromised rather than acting maliciously. The incident underscores North Korea's continued focus on cryptocurrency theft and software supply chain attacks.

Wiz says a supply chain attack that infected arrayref, a Rust package present in roughly three-quarters of Rust-running environments, drew comparisons to recent North Korean operations.

The malicious update hid a backdoor that steals credentials within code designed to run automatically during user project compilation. Thus, anyone who compiled a project on Thursday could now have compromised their computer and their secrets.

Why is North Korea being blamed for hacking ArrayRef?

Wiz researchers Rami McCarthy and Benjamin published a report noting that the arrayref payload routes signals to the control channel /49890878, which also appears in the Mastra campaign.

Microsoft links the Mastra campaign to a North Korean hacking group it calls Sapphire Sleet.

The internet address (IP) used in the arrayref attack has the same security certificate as another address used in Mastra. Additionally, a victim reporting suspicious activity noted an IP address that Google Cloud discovered in an axios npm attack.

Mandiant states the attack was carried out by a North Korean group called UNC1069. Both attacks used the same hosting company, Hostwinds.

The attack was hard to spot because it changed almost nothing. Ilya Makari, a security researcher from Aikido, discovered that the code itself within three Rust packages—arrayref, internment, and append-only-vec—was not altered. The only change was the addition of one new dependency to each package's list called proc-macro1.

This name is a misspelling of the popular crate proc-macro2, which has been downloaded over 154 million times. The fake crate even includes real proc-macro2 code, so the software still compiles and passes all tests.

The malicious part was hidden in the build script.

The Rust Security Response Team explained that simply compiling a project using the flawed version was enough to trigger the attack.

After execution, the second stage of the attack stole saved passwords from Chrome, Brave, and Edge browsers and installed itself to persist after computer restart on Windows, Mac, and Linux.

The Largest Rust Compromise by Number of Downloads

Aikido stated this attack is the largest Rust crate hack it has encountered, judged by download numbers: arrayref, used in tools for Solana and Ethereum, was downloaded approximately 244 million times. The vulnerability reportedly persisted for 86 minutes before being removed.

The team reported that the initial report came fromtron Systems. After detecting the attack, the team deleted the clean versions and blocked the developer account.

The Rust development team stated it does not believe the author's actions were malicious, suspecting their computer ordent data was compromised.

Notably, Amazon reported a link between several npm library hacks and a single entity linked to North Korea. TRM Labs also reported that North Korean groups accounted for about 76% of all cryptocurrency hack amounts between April 2026 (approximately $577 million).

Black Hat researcher Vangelis Stykas said he tracks North Korean hackers who have breached 1,640 companies in 57 countries. He found they often lure developers with fake job offers that install malware, similar to the poisoned build dependency in this case.

end-content

Perguntas relacionadas

QWhat is the key malicious update discovered in the Rust package arrayref, and how does it work?

AThe malicious update introduced a misspelled dependency named 'proc-macro1' (instead of the legitimate 'proc-macro2'). This fake crate contained the real library's code to pass compilation and tests, but its build script hid a backdoor that stole credentials. Simply compiling a project that used the compromised version triggered the attack.

QWhich security researchers are credited with the primary report linking the arrayref supply chain attack to North Korean hackers?

AWiz researchers Rami McCarthy and Benjamen published the report. They noted that the attack's command-and-control channel was linked to the North Korean Mastra campaign, which Microsoft attributes to the group Sapphire Sleet.

QWhy was the attack on the arrayref Rust crate particularly difficult to detect?

AThe attack was hard to detect because the actual source code of the three targeted Rust packages (arrayref, internment, and append-only-vec) wasn't changed. The only modification was the addition of a single new, malicious dependency ('proc-macro1') to each package's list, making the change appear minimal and legitimate.

QWhat makes the arrayref compromise significant in the context of Rust ecosystem security incidents?

AAccording to Aikido, this is the largest Rust crate compromise they have encountered based on download count. The affected crate, arrayref, is used in tools for Solana and Ethereum and has been downloaded approximately 244 million times.

QHow do North Korean hacking groups commonly target developers, as referenced in the article?

AAs noted by Black Hat researcher Vangelis Stykas, North Korean hackers often lure developers with fake job offers. These offers are designed to trick developers into installing malware, similar to the poisoned build dependency used in the arrayref attack.

Leituras Relacionadas

Trading

Spot
活动图片