BTC $77,390.39 +6.55%
ETH $2,424.71 +4.18%
BNB $679.30 +4.53%
XRP $1.39 +10.59%
SOL $91.89 +5.41%
TRX $0.3402 +0.38%
DOGE $0.0850 +5.29%
ADA $0.2202 +11.17%
BCH $295.23 +32.35%
LINK $11.65 +8.97%
HYPE $75.08 +4.47%
AAVE $111.46 +15.19%
SUI $0.8177 +11.66%
XLM $0.1938 +5.99%
ZEC $669.90 +18.36%
BTC $77,390.39 +6.55%
ETH $2,424.71 +4.18%
BNB $679.30 +4.53%
XRP $1.39 +10.59%
SOL $91.89 +5.41%
TRX $0.3402 +0.38%
DOGE $0.0850 +5.29%
ADA $0.2202 +11.17%
BCH $295.23 +32.35%
LINK $11.65 +8.97%
HYPE $75.08 +4.47%
AAVE $111.46 +15.19%
SUI $0.8177 +11.66%
XLM $0.1938 +5.99%
ZEC $669.90 +18.36%

The Rust standard library arrayref was attacked in a supply chain incident, suspected to be by North Korean hackers

2026-08-21 10:54:54

According to Cryptopolitan, attackers released malicious versions of three widely used Rust packages through a supply chain attack, with a library named arrayref being used by about three-quarters of Rust development environments. The malicious update hid a backdoor that could automatically steal login information when users compiled projects; users who compiled the affected versions may have exposed their computers and keys.

Wiz researchers pointed out that the command and control path of the arrayref attack overlaps with the Mastra operation used by the North Korean hacker groups Sapphire Sleet and UNC1069, with IP addresses sharing the same security certificate and using the same hosting provider, Hostwinds. The attackers only added a misspelled proc-macro1 dependency, mimicking the popular proc-macro2, without modifying the original code, allowing it to pass tests and builds. The attack was removed 86 minutes after release but had already been downloaded extensively. The affected packages are widely used in Solana and Ethereum tools. The Rust team believes the maintainer's actions were not malicious, and their device or credentials may have been compromised.

app_icon
ChainCatcher Building the Web3 world with innovations.