North Korean Hackers Suspected in Rust Supply Chain Attack
Cybersecurity researchers have identified suspected North Korean hackers as the perpetrators of a supply chain attack targeting Rust's Arrayref and other critical dependencies.
The attack occurred on August 20, when malicious versions of three Rust crates - arrayref (@0.3.10), append-only-vec (@0.1.9), and internment (@0.8.7) - were published on crates.io.
The credentials or machine of Arrayref's legitimate maintainer was compromised, allowing the attackers to upload tampered versions that introduced a dependency on the malicious package proc-macro1.
The build script executed malicious code during the software packaging process, which integrated functions designed to extract browser credentials and access local storage of crypto wallet extensions.
A technical analysis by Aikido revealed significant technical overlaps between the servers used in this attack and previous campaigns attributed to the Pyongyang regime.
The Wiz Threat Intelligence team reported that the command and control (C2) infrastructure utilized IP address ranges associated with hosting provider Hostwinds LLC, which had previously appeared in reports linked to the advanced persistent threat group UNC1069.