Rust Library arrayref Targeted in Supply Chain Attack Linked to North Korean Hackers
Attackers launched a supply chain attack by releasing malicious versions of three widely used Rust packages, including arrayref, which is utilized by approximately 75% of Rust development environments. The malicious update contained a backdoor designed to steal login credentials during project compilation. Wiz researchers noted that the command-and-control infrastructure overlaps with operations attributed to North Korean hacker groups Sapphire Sleet and UNC1069. A