Back to Feed
Supply ChainAug 21, 2026

Rust Supply Chain Attack Linked to North Korean Hackers

North Korean hackers compromised Rust's arrayref crate, injecting malicious code to steal data.

Summary

North Korean threat actors, identified as Sapphire Sleet, have compromised the popular Rust crate 'arrayref' in a supply chain attack. The attackers pushed a malicious version that fetched a second-stage binary, disabling certificate validation. While the Rust Security Response Team removed the malicious packages, the incident highlights the ongoing threat to open-source software ecosystems.

Full text

North Korean hackers are responsible for a new open source software (OSS) supply chain attack targeting the Rust ecosystem, cybersecurity firm Wiz reports. The attack occurred on August 20 and involved one of the most popular Rust crates, arrayref, an array-conversion utility with over 245 million downloads, found in approximately 75% of environments where Rust is used. The malicious package version, [email protected], was pushed to crates.io from its legitimate maintainer’s account. Roughly 20 minutes later, poisoned versions of internment and append-only-vec, two crates from the same owner, were also released. These packages, as well as attacker-owned crates (aovine, arone, aronenao, tinymember), were referencing the same malicious dependency, [email protected], which impersonated the legitimate proc-macro2 package. Within the dependency, the threat actor hid a malicious file, build.rs, designed to fetch a platform-specific second-stage binary over TLS, after disabling certificate validation. The Rust Security Response Team removed the malicious packages roughly 86 minutes later, confirming the compromise: “a new version of the arrayref crate was published with a direct dependency on proc-macro1, which would execute a malicious build script.”Advertisement. Scroll to continue reading. Shortly after, the Rust security team said all malicious packages have been removed, and the clean iterations have been restored. The team found no evidence of actual usage of the malicious crates. “We do not believe the author of arrayref to be acting maliciously, but their computer or credentials are likely compromised, and we are attempting to contact them,” Rust’s security team said. StepSecurity’s analysis of the attack shows that the threat actor planned each step with precision, creating typosquatted versions of proc-macro2 and an impersonating account right before the poisoned arrayref release was published. According to Wiz, the North Korean threat actor Sapphire Sleet, which mounted the Axios and Mastra NPM supply chain attacks in April and June, was likely responsible for the arrayref incident, based on substantial infrastructure overlaps. The arrayref payloads beacon to an endpoint used in the Mastra attack, command-and-control (C&C) traffic was recorded to an IP used in the Axios campaign, and the same IP range of Hostwinds LLC infrastructure was used in all three incidents. Related: Fortune 500 Companies Hit in Azure Data Theft Campaign Related: Trivy, Not LiteLLM Behind the 2,500 Org Compromise Related: Hackers Target Zimbra Servers in Active Exploitation Campaign Related: AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Cisco Patches Critical Crosswork, Secure Workload VulnerabilitiesExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerCritical GitLab Flaw Exploited Shortly After DisclosurePrevalent AI Raises $22 Million to Expand Data Fabric PlatformUS Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of ThemCISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities943 Patches Rolled Out With Oracle’s August 2026 Security UpdateChrome, Firefox Updates Patch Dozens of Vulnerabilities Latest News Contractors’ CMMC Confidence Rises as Ability to Prove It Falls BehindMicrosoft Rolls Out 22 Fresh Security PatchesCISA Urges Immediate Patching of Exploited TrueConf VulnerabilitiesHackers Target Zimbra Servers in Active Exploitation CampaignSurveillance – Everything You Wanted to Know, But Were Afraid to AskThreat Actor Hacks 14,000 IP Cameras in Ukraine and RussiaAtlassian, Splunk Patch Dozens of Critical, High-Severity VulnerabilitiesMLflow Vulnerability Exploited for Cloud Credential Theft Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveDaniel Dubowski has been named Senior Vice President and Chief Information Security Officer at Marriott International.Allied Universal has named Jordan Avnaim Global Chief Information Security Officer.Cycode has promoted Seth Robbins to President and Chief Revenue Officer.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • malware — build.rs

Entities

Sapphire Sleet (threat_actor)arrayref (product)internment (product)append-only-vec (product)proc-macro2 (product)Axios (campaign)