Researchers Link Arrayref Library Hack in Rust to North Korean Hackers

cryptonews.ruОпубліковано о 2026-08-20Востаннє оновлено о 2026-08-20

Анотація

Researchers link the hack of the Rust 'arrayref' library to North Korean hackers, in a major software supply chain attack. The malicious update, which was live for 86 minutes, added a malicious dependency named 'proc-macro1' to the arrayref, internment, and append-only-vec packages. This typo-squatted on the legitimate 'proc-macro2' crate and concealed a backdoor in the build script. Compiling a project using the compromised version was enough to trigger the attack, which stole saved passwords from browsers like Chrome, Brave, and Edge across Windows, Mac, and Linux systems. With approximately 244 million downloads, this is considered the largest Rust crate compromise by download volume. Security firms Wiz, Mandiant, and others attribute the attack to North Korean groups like Sapphire Sleet (Microsoft) or UNC1069 (Mandiant), citing infrastructure overlaps with other campaigns like Mastra. The Rust Security team removed the packages and blocked the developer account, though they believe the developer's account was compromised rather than acting maliciously. The incident underscores North Korea's continued focus on cryptocurrency theft and software supply chain attacks.

Wiz says a supply chain attack that infected arrayref, a Rust package present in roughly three-quarters of Rust-running environments, drew comparisons to recent North Korean operations.

The malicious update hid a backdoor that steals credentials within code designed to run automatically during user project compilation. Thus, anyone who compiled a project on Thursday could now have compromised their computer and their secrets.

Why is North Korea being blamed for hacking ArrayRef?

Wiz researchers Rami McCarthy and Benjamin published a report noting that the arrayref payload routes signals to the control channel /49890878, which also appears in the Mastra campaign.

Microsoft links the Mastra campaign to a North Korean hacking group it calls Sapphire Sleet.

The internet address (IP) used in the arrayref attack has the same security certificate as another address used in Mastra. Additionally, a victim reporting suspicious activity noted an IP address that Google Cloud discovered in an axios npm attack.

Mandiant states the attack was carried out by a North Korean group called UNC1069. Both attacks used the same hosting company, Hostwinds.

The attack was hard to spot because it changed almost nothing. Ilya Makari, a security researcher from Aikido, discovered that the code itself within three Rust packages—arrayref, internment, and append-only-vec—was not altered. The only change was the addition of one new dependency to each package's list called proc-macro1.

This name is a misspelling of the popular crate proc-macro2, which has been downloaded over 154 million times. The fake crate even includes real proc-macro2 code, so the software still compiles and passes all tests.

The malicious part was hidden in the build script.

The Rust Security Response Team explained that simply compiling a project using the flawed version was enough to trigger the attack.

After execution, the second stage of the attack stole saved passwords from Chrome, Brave, and Edge browsers and installed itself to persist after computer restart on Windows, Mac, and Linux.

The Largest Rust Compromise by Number of Downloads

Aikido stated this attack is the largest Rust crate hack it has encountered, judged by download numbers: arrayref, used in tools for Solana and Ethereum, was downloaded approximately 244 million times. The vulnerability reportedly persisted for 86 minutes before being removed.

The team reported that the initial report came fromtron Systems. After detecting the attack, the team deleted the clean versions and blocked the developer account.

The Rust development team stated it does not believe the author's actions were malicious, suspecting their computer ordent data was compromised.

Notably, Amazon reported a link between several npm library hacks and a single entity linked to North Korea. TRM Labs also reported that North Korean groups accounted for about 76% of all cryptocurrency hack amounts between April 2026 (approximately $577 million).

Black Hat researcher Vangelis Stykas said he tracks North Korean hackers who have breached 1,640 companies in 57 countries. He found they often lure developers with fake job offers that install malware, similar to the poisoned build dependency in this case.

end-content

Пов'язані питання

QWhat is the key malicious update discovered in the Rust package arrayref, and how does it work?

AThe malicious update introduced a misspelled dependency named 'proc-macro1' (instead of the legitimate 'proc-macro2'). This fake crate contained the real library's code to pass compilation and tests, but its build script hid a backdoor that stole credentials. Simply compiling a project that used the compromised version triggered the attack.

QWhich security researchers are credited with the primary report linking the arrayref supply chain attack to North Korean hackers?

AWiz researchers Rami McCarthy and Benjamen published the report. They noted that the attack's command-and-control channel was linked to the North Korean Mastra campaign, which Microsoft attributes to the group Sapphire Sleet.

QWhy was the attack on the arrayref Rust crate particularly difficult to detect?

AThe attack was hard to detect because the actual source code of the three targeted Rust packages (arrayref, internment, and append-only-vec) wasn't changed. The only modification was the addition of a single new, malicious dependency ('proc-macro1') to each package's list, making the change appear minimal and legitimate.

QWhat makes the arrayref compromise significant in the context of Rust ecosystem security incidents?

AAccording to Aikido, this is the largest Rust crate compromise they have encountered based on download count. The affected crate, arrayref, is used in tools for Solana and Ethereum and has been downloaded approximately 244 million times.

QHow do North Korean hacking groups commonly target developers, as referenced in the article?

AAs noted by Black Hat researcher Vangelis Stykas, North Korean hackers often lure developers with fake job offers. These offers are designed to trick developers into installing malware, similar to the poisoned build dependency used in the arrayref attack.

Пов'язані матеріали

Morgan Stanley Research Report Analysis: Treasury's Repurchase Scale Doubles, The Logic for a Steepening Yield Curve Remains Unchanged

Morgan Stanley report: US Treasury doubles long-term bond buyback size, steepening yield curve thesis intact. The US Treasury will double the size of its regular liquidity support buyback operations for 10-20 year and 20-30 year bonds to at least $4 billion per operation starting Sept 9. Morgan Stanley views this move, the first adjustment outside a quarterly refunding window since the program's May 2024 launch, as a more important signal than the buybacks themselves. The Treasury is signaling close attention to long-end yield dynamics, using the tool to buy time ahead of the November refunding where it could cut long-term issuance. The report argues recent long-end yield rises and curve steepening are driven not by supply/deficit concerns but by repricing of energy prices and central bank policy paths. Analysis of cash Treasury vs. swap spreads shows no clear pattern consistent with dominant supply worries. The action echoes a November 2023 "supply surprise" that briefly flattened the curve. MS maintains its recommendation to steepen the 7s30s curve, targeting a 100 bps spread vs. ~71 bps currently. It believes fundamentals—cooling inflation, weaker-than-expected labor data, and potential downward revision of the Fed's terminal rate—will ultimately drive markets, supporting further steepening. In FX, MS strategists note the move was interpreted as a mild tool to curb USD strength. A refocus on USD policy could lead to further weakness, particularly against CHF, with EUR/USD potentially rising toward 1.2150.

marsbit29 хв тому

Morgan Stanley Research Report Analysis: Treasury's Repurchase Scale Doubles, The Logic for a Steepening Yield Curve Remains Unchanged

marsbit29 хв тому

Kaito Revives 'Talk-to-Earn' Economy, But Many Are Hesitant to Install the New Plugin

Kaito AI has launched a new browser extension called Kaito Pulse, aiming to integrate users' discussions on X (formerly Twitter) with their on-chain activities and social influence to build a new "attention + behavior verification" scoring system. The plugin displays users' public trading positions from platforms like Polymarket directly on the X timeline, allowing others to assess if their statements align with their actual market behavior. This move is seen as reviving "influence-to-earn" incentives. However, the launch sparked significant privacy concerns. Critics, including an analysis by "Ultra," allege the extension collects extensive data, such as device fingerprints (via GPU, hardware info), X user behavior (browsing paths, clicks), and may access sensitive data from third-party accounts (e.g., ChatGPT, trading platforms). This raised debates about trading privacy for verified influence. In response, Kaito founder Yu Hu stated the design follows data minimization principles, aiming to generate verification proofs without collecting or storing raw user data, using technologies like zkTLS. He acknowledged some permission descriptions could be misleading and promised improvements. The controversy highlights a core dilemma for social finance (SocialFi) platforms: as fake engagement and AI content grow, more user data is needed to verify genuine influence, but this risks encroaching on user privacy and trust.

marsbit30 хв тому

Kaito Revives 'Talk-to-Earn' Economy, But Many Are Hesitant to Install the New Plugin

marsbit30 хв тому

Kaito Reboots 'Talk-to-Earn Economy', but Many Are Hesitant to Install the New Plugin

Kaito AI has launched a new browser extension called Kaito Pulse, aiming to revitalize what the community terms the "talk-to-earn" or "social-fi" economy on X (formerly Twitter). The plugin displays users' on-chain trading activity, such as positions from platforms like Polymarket, directly within the X timeline. This aims to create a new "attention + behavior verification" system, shifting focus from who generates the most discussion to whose discussions are backed by credible, verifiable actions. However, the launch quickly sparked significant privacy concerns within the crypto community. Critics, led by an analysis from user "Ultra," allege the extension's code enables deep data collection. This includes potential device fingerprinting (using GPU, hardware, and audio data), tracking of X user behavior (browsing paths, clicks, engagement), and verification processes that could access sensitive data from third-party accounts like ChatGPT, Claude, and trading platforms. The debate centers on whether such extensive verification is necessary to combat fake engagement and AI-generated content, or if it constitutes an unacceptable privacy sacrifice. In response, Kaito founder Yu Hu stated the design follows data minimization principles. He claimed Kaito Pulse does not collect or store users' raw data but instead uses verification techniques, including zkTLS, to generate proofs of identity or behavior without exposing the underlying information. Yu Hu acknowledged that some permission descriptions could be misleading and promised improvements in future versions. The controversy highlights a core dilemma for social-fi projects: platforms need more user data to distinguish real influence from artificial hype, but users must decide how much privacy they are willing to trade for potential rewards and ranking within these new incentive systems.

Odaily星球日报50 хв тому

Kaito Reboots 'Talk-to-Earn Economy', but Many Are Hesitant to Install the New Plugin

Odaily星球日报50 хв тому

Торгівля

Спот
活动图片