North Korean Hackers Suspected in Rust Supply Chain Attack Targeting Arrayref

TL;DR:
- Affected packages: Malicious versions of the Rust crates arrayref (@0.3.10), append-only-vec (@0.1.9), and internment (@0.8.7) were published on crates.io on August 20, 2026.
- Library scope: The arrayref crate accounts for over 244 million cumulative downloads and is present across three-quarters of environments where Rust operates.
- Security response: The Rust Security Response Team removed the compromised packages after they remained active for 86 to 107 minutes on the official registry.
Cybersecurity researchers identified the suspected involvement of North Korean hackers in a โฆ Continue reading the full article at the original source below.
This content is automatically aggregated. Full credit goes to the original publisher (crypto-economy.com).


