logo

North Korean Hackers Tied to Rust Supply Chain Attack

ID: b57bb524-318c-5d71-893a-b86c0dce40ab

STIX ID: report--b57bb524-318c-5d71-893a-b86c0dce40ab

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-08-21

Date Updated: 2026-08-22

...
...

Wiz researchers linked a supply-chain campaign that compromised several popular Rust crates on crates.io (arrayref, internment, append-only-vec) to North Korean state-sponsored actors. The attacker altered package manifests to depend on a typosquatted crate (proc-macro1) which executed during compilation, allowing the payload to harvest browser credentials, crypto wallet extensions and developer secrets; telemetry indicated wide exposure (arrayref present in ~75% of cloud Rust environments). The Rust Security Response Team revoked the maintainer's credentials and removed malicious versions, and organizations are advised to treat systems that compiled the tainted crates as compromised and rotate secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.