PANews
PANews|Aug 21, 2026 02:54
[Rust Core Library arrayref Targeted by Supply Chain Attack, Suspected to Be the Work of North Korean Hackers] According to Cryptopolitan, on August 20, attackers carried out a supply chain attack by releasing malicious versions of three widely used Rust code packages, including a library named arrayref, which is utilized by approximately three-quarters of Rust development environments. The malicious update concealed a backdoor capable of automatically stealing login credentials when users compiled their projects. Users who compiled the affected versions may have exposed their computers and keys. Wiz researchers pointed out that the command-and-control path of the arrayref attack overlaps with the Mastra operation used by North Korean hacker groups Sapphire Sleet and UNC1069. The IP address shares the same security certificate and uses the same hosting provider, Hostwinds.
+1
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads