Rust Crate arrayref Poisoned in Attack Tied to DPRK Infrastructure

2026-08-22 Cloud Security Alliance

https://labs.cloudsecurityalliance.org/research/csa-research-note-arrayref-rust-supply-chain-dprk-overlap-20/

Attachments

source_4018.pdf (2 MB)

Thumbnail for Rust Crate arrayref Poisoned in Attack Tied to DPRK Infrastructure

Attackers compromised a crates.io maintainer account and poisoned arrayref, internment, and append-only-vec with a malicious proc-macro1 build dependency that executed during compilation. The resulting implant stole browser credentials, established cross-platform persistence, and supported remote commands and fallback C2. CSA highlights endpoint, TLS certificate, and hosting-infrastructure overlap with earlier Sapphire Sleet and UNC1069 supply-chain campaigns, but treats that overlap as suggestive rather than a formal DPRK attribution. The incident is tracked as CVE-2026-77651 and RUSTSEC-2026-0260.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 23.254.165.112 2026-08-20 2026-08-22

Related Actors

Related Reports

« Back