Rust Supply Chain Attack Linked to North Korean Hackers

Rust Supply Chain Attack Linked to North Korean Hackers
North Korean hackers conducted a supply chain attack against the Rust ecosystem by poisoning the popular arrayref crate and related packages on crates.io. Wiz linked the operation to Sapphire Sleet, noting infrastructure overlaps with earlier Axios and Mastra NPM campaigns and a malicious dependency impersonating proc-macro2. #SapphireSleet #arrayref #proc-macro2 #crates.io

Keypoints

  • A malicious version of arrayref was published from the maintainer’s account on August 20.
  • Poisoned versions of internment and append-only-vec were released shortly after.
  • The packages referenced a fake proc-macro2 dependency that hid a malicious build.rs file.
  • The payload was designed to download a second-stage binary over TLS with certificate validation disabled.
  • Wiz attributed the attack to Sapphire Sleet based on shared infrastructure with prior campaigns.

Read More: https://www.securityweek.com/rust-supply-chain-attack-linked-to-north-korean-hackers/