Rust Crate arrayref Poisoned in Attack Tied to DPRK Infrastructure
2026-08-22 • Cloud Security Alliance •
Attachments
source_4018.pdf (2 MB)
Attackers compromised a crates.io maintainer account and poisoned arrayref, internment, and append-only-vec with a malicious proc-macro1 build dependency that executed during compilation. The resulting implant stole browser credentials, established cross-platform persistence, and supported remote commands and fallback C2. CSA highlights endpoint, TLS certificate, and hosting-infrastructure overlap with earlier Sapphire Sleet and UNC1069 supply-chain campaigns, but treats that overlap as suggestive rather than a formal DPRK attribution. The incident is tracked as CVE-2026-77651 and RUSTSEC-2026-0260.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 23.254.165.112 | 2026-08-20 | 2026-08-22 |