Rust Supply Chain Attack Linked to North Korean Hackers
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server. The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek.
North Korean hackers are responsible for a new open source software (OSS) supply chain attack targeting the Rust ecosystem, cybersecurity firm Wiz reports.
The attack occurred on August 20 and involved one of the most popular Rust crates, arrayref, an array-conversion utility with over 245 million downloads, found in approximately 75% of environments where Rust is used.
The malicious package version, [email protected], was pushed to crates.io from its legitimate maintainer’s account. Roughly 20 minutes later, poisoned versions of internment and append-only-vec, two crates from the same owner, were also released.
Source: https://www.securityweek.com/rust-supply-chain-attack-linked-to-north-korean-hackers/
Related breach coverage
- North Korean Hackers Deploy New Linux Espionage Toolkit2026-09-07
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek.
- AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million2026-09-03
The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks. The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek.
- Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows2026-09-17
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.
- Surfshark Systems Targeted by Hackers2026-09-11
A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors. The post Surfshark Systems Targeted by Hackers appeared first on SecurityWeek.