Loading...
According to Cryptopolitan, attackers have released three malicious versions of Rust code packages through supply chain attacks, with the arrayref library being used by approximately three-quarters of Rust development environments. Malicious updates contain a backdoor that can steal login information when users compile projects. Wiz researchers pointed out that the command and control path of the arrayref attack overlaps with the Mastra operation used by North Korean hacker groups Sapphire Sleet and UNC1069, with IP addresses sharing the same security certificate and using the same hosting provider Hostwins.