Live Cybersecurity News Ticker | Codekeeper

Suspected North Korean Hackers Targeted Popular Rust Packages in Supply Chain Attack

Written by Content Team | Aug 24, 2026, 5:30:13 AM

North Korean hacking group Sapphire Sleet is the likely suspect behind a Rust ecosystem supply chain attack on August 20, which compromised arrayref — a package with over 245 million downloads found in roughly 75% of Rust environments. The attackers pushed a malicious version from the legitimate maintainer's account, then quickly poisoned two more related crates. Hidden inside was a build script designed to fetch a second-stage payload over TLS with certificate validation disabled.

The Rust Security Response Team yanked the malicious packages within 86 minutes. No evidence of actual exploitation was found. Wiz tied the attack to Sapphire Sleet based on infrastructure overlaps with earlier NPM attacks targeting Axios and Mastra.

Source: SecurityWeek