CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4815

As cited

Copy frozen at (site build).

threat intel

Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns

Malicious versions of the arrayref Rust crate and related packages executed backdoors during compilation. The attack infrastructure shows significant overlap with confirmed Democratic People's Republic of Korea (DPRK) supply chain campaigns, including those targeting Mastra and axios.

Why it matters: Rust developers and maintainers of Rust dependencies are at risk; this indicates nation-state actors are actively compromising widely-used packages to inject code into downstream software builds.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns

Malicious versions of the arrayref Rust crate and related packages executed backdoors during compilation. The attack infrastructure shows significant overlap with confirmed Democratic People's Republic of Korea (DPRK) supply chain campaigns, including those targeting Mastra and axios.

Why it matters: Rust developers and maintainers of Rust dependencies are at risk; this indicates nation-state actors are actively compromising widely-used packages to inject code into downstream software builds.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary