Researchers tie the arrayref Rust crate hijack to North Korean hackers

Source Cryptopolitan

Wiz says the supply chain attack that poisoned arrayref, a Rust package present in roughly three-quarters of environments running Rust, has drawn comparisons with recent North Korean operations. 

The harmful update hid a backdoor that steals login information inside a code designed to run automatically when users compile projects. So, anyone who compiled a project on Thursday may now have exposed their computer and secrets.

Why is North Korea being blamed for the hack on arrayref? 

Wiz researchers Rami McCarthy and Benjamin Read have published a report in which they noted that the arrayref payload beacons to a command-and-control path, /49890878, that also appears in the Mastra campaign. 

Microsoft links the Mastra campaign to a North Korean hacking group it calls Sapphire Sleet. 

The internet address (IP) used in the arrayref attack shares the same security certificate as another address used in Mastra. Also, a victim who reported suspicious activity flagged an IP that Google Cloud saw in the axios npm attack. 

Mandiant says that the attack was done by a North Korean group called UNC1069. Both attacks used the same hosting company, Hostwinds.

The attack was hard to notice because it changed very little. Ilyas Makari, a security researcher from Aikido, found that the actual code inside the three Rust packages, arrayref, internment, and append-only-vec, was not altered. The only change was one new dependency added to each package’s list called proc-macro1.

This name is a misspelling of the popular proc-macro2 crate, which has over 154 million downloads. The fake crate even includes the real proc-macro2 code, so the software still builds and passes all tests. 

The harmful part was hidden in the build script. 

Cargo runs build scripts automatically at compile time, so, as the Rust Security Response Team spelled out in its advisory, merely compiling a project that pulled the bad version was enough to trigger the attack. 

Once running, the second stage of the attack stole saved passwords from Chrome, Brave, and Edge browsers and installed itself so it would survive computer restarts on Windows, Mac, and Linux.

The largest Rust compromise by download count

Aikido stated that this attack is the biggest Rust crate compromise it has seen, measured by downloads, with arrayref, which is used in tools for Solana and Ethereum, sitting at about 244 million total downloads. The exposure was reportedly live for 86 minutes before deletion. 

The team said Nextron Systems made the initial report. And once the attack was discovered, the team unyanked the clean versions and locked the maintainer’s account. 

The Rust team said it does not believe the author acted maliciously, assessing instead that their machine or credentials were compromised. 

Notably, Amazon disclosed on July 29 that it had linked a string of npm library compromises to a single DPRK-linked actor. TRM Labs also reported that North Korean groups accounted for about 76% of all crypto hack value in 2026 through April (roughly $577 million). 

Black Hat researcher Vangelis Stykas has said he tracked North Korean hackers into 1,640 companies across 57 countries. He found that they often bait developers with fake job offers that install malware, similar to the poisoned build dependency in this case. 

The smartest crypto minds already read our newsletter. Want in? Join them.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Why the S&P 500’s Path to 9,000 Runs Into Trouble in 2027The boldest S&P 500 forecast on Wall Street sees 9,000 by year-end, roughly 17% above where the index trades now. The fuel is the AI boom and a wall of idle cash.The warning is that the same AI trade
Author  Beincrypto
20 hours ago
The boldest S&P 500 forecast on Wall Street sees 9,000 by year-end, roughly 17% above where the index trades now. The fuel is the AI boom and a wall of idle cash.The warning is that the same AI trade
placeholder
Treasury Just Drew a Line in the Sand at 5.3%, and Bitcoin NoticedThe US Treasury said Wednesday it will at least double the size of its long-end debt buybacks. The 30-year yield reversed sharply from a 19-year high, and Bitcoin climbed past $65,000.The larger opera
Author  Beincrypto
20 hours ago
The US Treasury said Wednesday it will at least double the size of its long-end debt buybacks. The 30-year yield reversed sharply from a 19-year high, and Bitcoin climbed past $65,000.The larger opera
placeholder
Crypto Prices Explode With Surprise Rally: Is the Bull Market Back? Bitcoin (BTC) jumped 5.8% to levels above $69,500 on Wednesday, wiping out $1.23 billion in bets against it in one hour. Is the crypto bull market back?The rally ran market-wide, with Ethereum (ETH) u
Author  Beincrypto
20 hours ago
Bitcoin (BTC) jumped 5.8% to levels above $69,500 on Wednesday, wiping out $1.23 billion in bets against it in one hour. Is the crypto bull market back?The rally ran market-wide, with Ethereum (ETH) u
placeholder
Bitcoin is a “Cheat Code” to Retire Without Selling, Analyst Explains WhyBitcoin functions as a genuine cheat code for retiring without ever selling, according to analyst and entrepreneur Mark Moss, who laid out that thesis in a recent Coin Stories podcast interview.His ce
Author  Beincrypto
20 hours ago
Bitcoin functions as a genuine cheat code for retiring without ever selling, according to analyst and entrepreneur Mark Moss, who laid out that thesis in a recent Coin Stories podcast interview.His ce
placeholder
Eli Lilly Price Forecast: The Next Big Stock After Weight-Loss Drug Breakthrough?Eli Lilly is one of the most popular names today in America’s weight-loss and diabetes drug market. Its drugs delivered an average weight loss of 28.3% in a Phase 3 trial, approaching results historic
Author  Beincrypto
20 hours ago
Eli Lilly is one of the most popular names today in America’s weight-loss and diabetes drug market. Its drugs delivered an average weight loss of 28.3% in a Phase 3 trial, approaching results historic
goTop
quote