North Korean Hackers Suspected in Massive Rust Supply Chain Attack
A major security incident has been reported in the Rust programming ecosystem, affecting developers and cryptocurrency holders. Attackers compromised a widely used code library called arrayref, which is a popular package among software developers.
The breach was discovered after researchers found that attackers had obtained the login credentials of arrayref's legitimate maintainer or gained direct access to their machine. This allowed them to publish altered versions of the package on the public registry, introducing a dependency on a previously unknown package called proc-macro1.
The malicious code hid inside the build process and extracted saved browser credentials as well as data stored by cryptocurrency wallet browser extensions. The attackers' command and control setup relied on IP address ranges associated with hosting provider Hostwinds LLC, which were previously linked to North Korean state-sponsored hacking groups.
Rust developers and organizations are advised to review their Cargo.lock files for the affected package versions, remove any dependency on proc-macro1, rotate credentials, and monitor browser-stored credentials and crypto wallet extensions for unusual activity. The Rust Security Response Team is continuing its audit into the compromised credentials and broader scope of the campaign.