As cited
Copy frozen at (site build).
threat intel
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Malicious versions of the arrayref Rust crate and related packages executed backdoors during compilation. The attack infrastructure shows significant overlap with confirmed Democratic People's Republic of Korea (DPRK) supply chain campaigns, including those targeting Mastra and axios.
Why it matters: Rust developers and maintainers of Rust dependencies are at risk; this indicates nation-state actors are actively compromising widely-used packages to inject code into downstream software builds.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Malicious versions of the arrayref Rust crate and related packages executed backdoors during compilation. The attack infrastructure shows significant overlap with confirmed Democratic People's Republic of Korea (DPRK) supply chain campaigns, including those targeting Mastra and axios.
Why it matters: Rust developers and maintainers of Rust dependencies are at risk; this indicates nation-state actors are actively compromising widely-used packages to inject code into downstream software builds.
- Source published
- First seen by Cybersecurity Tracker