Hackers Poison Arrayref Rust Crate to Push Infostealer Malware
The poisoned releases ran during compilation and stole browser credentials and crypto keys before removal, with arrayref alone drawing more than 245 million downloads.
- Hackers compromised a trusted maintainer account this week, pushing malicious updates to widely used Rust crates including Arrayref and Append-only-vec that infected developer machines during routine software builds via Cargo.
- Nextron Systems researchers flagged a suspicious crate, prompting The Rust Security Response Team to disclose the supply chain attack on Thursday after the malicious versions sat on the registry for 86, 90, and 107 minutes.
- Security firm Aikido found the malware targeted Chromium-based browsers like Chrome, Brave, and Microsoft Edge to steal credentials and crypto wallet data from developers using Arrayref, which has more than 245 million lifetime downloads.
- The Rust Security Response Team removed the compromised packages and locked the maintainer account, while urging developers to check their Cargo lockfiles and local registry caches for potential infections.
- Wiz analysts Rami McCarthy and Benjamin Read attributed the infrastructure to Sapphire Sleet, a North Korean state-sponsored group, suggesting adversaries are increasingly weaponizing developer ecosystems to gain access to downstream enterprise networks.
19 Articles
19 Articles
North Korean Hackers Hijack Popular Rust Crates in Hours-Long Supply Chain Strike
Hackers gained control of a trusted maintainer account this week and pushed malicious updates to three widely used Rust crates. The packages ran at build time. They stole credentials from browsers, crypto wallet extensions, and developer environments. The incident lasted barely two hours on crates.io. Yet its reach could stretch across hundreds of millions of downloads and thousands of production systems. The Rust Security Response Team disclose…
Hackers poison popular Rust crates to steal developers' credentials
Hackers slipped malware into several popular Rust packages this week, turning routine software builds into a route onto developers' machines. The Rust Security Response Team disclosed the supply chain attack on Thursday after receiving a tip about a crate called proc-macro1. An investigation found that its build script fetched malware from a remote server. The attack extended beyond a single dodgy crate. Someone had published a new version of ar…
Rust Supply Chain Attack Puts Solana-Adjacent Build Pipelines At Risk
The attack did not require a downstream vulnerability. Simply pulling in a tainted dependency and running a Cargo build was enough to trigger a remote payload, according to the original report. That shifted the risk from application exploitability to the developer workstation and continuous integration environment, where secrets, signing keys, and infrastructure access tend to live. Security researchers from SlowMist, Socket, and StepSecurity id…
Evidence of involvement by a North Korean-linked hacking group has once again been found in cyber attacks involving software components widely used worldwide.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium












