Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Rust Supply Chain Attack Linked to North Korean Hackers

    August 23, 2026

    NASA Shares Views of August Solar Eclipse from Ground, Air, Space

    August 23, 2026

    Apple’s rumored camera AirPods could bring cool AI features and a whole bunch of privacy concerns

    August 22, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Rust Supply Chain Attack Linked to North Korean Hackers
    Rust Supply Chain Attack Linked to North Korean Hackers
    Cybersecurity

    Rust Supply Chain Attack Linked to North Korean Hackers

    The Tech GuyBy The Tech GuyAugust 23, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    North Korean hackers are responsible for a new open source software (OSS) supply chain attack targeting the Rust ecosystem, cybersecurity firm Wiz reports.

    Advertisement

    The attack occurred on August 20 and involved one of the most popular Rust crates, arrayref, an array-conversion utility with over 245 million downloads, found in approximately 75% of environments where Rust is used.

    The malicious package version, [email protected], was pushed to crates.io from its legitimate maintainer’s account. Roughly 20 minutes later, poisoned versions of internment and append-only-vec, two crates from the same owner, were also released.

    These packages, as well as attacker-owned crates (aovine, arone, aronenao, tinymember), were referencing the same malicious dependency, [email protected], which impersonated the legitimate proc-macro2 package.

    Within the dependency, the threat actor hid a malicious file, build.rs, designed to fetch a platform-specific second-stage binary over TLS, after disabling certificate validation.

    The Rust Security Response Team removed the malicious packages roughly 86 minutes later, confirming the compromise: “a new version of the arrayref crate was published with a direct dependency on proc-macro1, which would execute a malicious build script.”

    Advertisement. Scroll to continue reading.

    Shortly after, the Rust security team said all malicious packages have been removed, and the clean iterations have been restored. The team found no evidence of actual usage of the malicious crates.

    “We do not believe the author of arrayref to be acting maliciously, but their computer or credentials are likely compromised, and we are attempting to contact them,” Rust’s security team said.

    StepSecurity’s analysis of the attack shows that the threat actor planned each step with precision, creating typosquatted versions of proc-macro2 and an impersonating account right before the poisoned arrayref release was published.

    According to Wiz, the North Korean threat actor Sapphire Sleet, which mounted the Axios and Mastra NPM supply chain attacks in April and June, was likely responsible for the arrayref incident, based on substantial infrastructure overlaps.

    The arrayref payloads beacon to an endpoint used in the Mastra attack, command-and-control (C&C) traffic was recorded to an IP used in the Axios campaign, and the same IP range of Hostwinds LLC infrastructure was used in all three incidents.

    Related: Fortune 500 Companies Hit in Azure Data Theft Campaign

    Related: Trivy, Not LiteLLM Behind the 2,500 Org Compromise

    Related: Hackers Target Zimbra Servers in Active Exploitation Campaign

    Related: AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

    August 22, 2026

    Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

    August 22, 2026

    Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

    August 22, 2026

    In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

    August 22, 2026

    Former NSA Director Paul Nakasone Launches National Security Advisory Firm

    August 21, 2026

    Critical Isolated-vm Vulnerability Leads to RCE on Host

    August 21, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Rust Supply Chain Attack Linked to North Korean Hackers

    August 23, 2026

    NASA Shares Views of August Solar Eclipse from Ground, Air, Space

    August 23, 2026

    Apple’s rumored camera AirPods could bring cool AI features and a whole bunch of privacy concerns

    August 22, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.