ZeroHour
Wiz Blogpublished ()ingested Rami McCarthy1

Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns

highThreat actor exploited in the wildimportance 72
AI summary · glm-5.3-flash

Malicious versions of the Rust crate arrayref executed a compile-time backdoor, with infrastructure overlapping recent DPRK supply chain attacks on Mastra and axios.

Wiz researchers report that malicious versions of the arrayref Rust crate ran a backdoor during compilation, compromising developer build pipelines. The campaign's command-and-control infrastructure significantly overlaps with infrastructure used in recent DPRK supply chain attacks, including campaigns against Mastra and axios. Developers using affected crate versions should audit their builds and review dependencies.

  • Malicious arrayref crate versions execute a backdoor at compile time
  • Infrastructure overlaps with DPRK supply chain campaigns on Mastra and axios
  • Highlights continued risk of open-source dependency compromises in the Rust ecosystem
VendorsWiz
Threat actorsDPRK
OrganizationsWiz
CountriesNorth Korea
Full article

Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.

This source does not provide full text. Read it at wiz.io.