Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Malicious versions of the Rust crate arrayref (and others) were published with a compile-time backdoor. The campaign infrastructure overlaps with known DPRK-attributed supply chain attacks including Mastra and axios.
- Disclosed
- Last updated
- Blast radius
- Rust ecosystem; any project depending on arrayref and related crates during the malicious version window
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- arrayrefRust crate with malicious versions executing compile-time backdoor
Malicious versions of the arrayref Rust crate were distributed via the cargo ecosystem with embedded backdoor code that executed at compile time. The attack affected multiple crates in the Rust supply chain.
The campaign's command-and-control infrastructure and operational patterns show significant overlap with previously documented DPRK-attributed supply chain attacks, including the Mastra and axios incidents. This attribution suggests a coordinated threat actor with established supply chain attack capabilities.
The incident was detected and disclosed by Wiz, indicating the malicious versions have been identified and the immediate threat contained. Affected projects should audit their dependencies and rebuild with clean versions of the crates.
Remediation
- Identify all projects that depend on arrayref or related affected crates during the malicious version window
- Rebuild and redeploy applications using patched/clean versions of the crates
- Audit build artifacts and runtime behavior for signs of compromise
- Review supply chain security practices and implement stricter dependency verification
- Monitor for indicators of compromise from the identified malicious infrastructure
Sources
Cite this entry
"Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 20, 2026; last updated August 20, 2026. https://supplychainattack.org/incident/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns-d1nnht
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in rust-testing-utils (npm)
The npm package rust-testing-utils contained malicious code that impersonates the pino logger and executes remotely-fetched code with arbitrary privileges. The package spawns a child process that decodes a hardcoded URL, fetches attacker-controlled content, and executes it via Function constructor with full module-loading capability.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in @syncraft-labs/core (npm)
The npm package @syncraft-labs/core contained obfuscated malicious code in its ESM build that executes on import, fetching and executing attacker-controlled payloads from Ethereum blockchain via JSON-RPC endpoints. The CommonJS build was clean, indicating targeted injection into the ESM entry point.
npmCompromised packageMalicious commit - containedcritical
Malicious code in reqcrypts (PyPI)
The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.
2026 08 ReqcryptPyPICompromised packageMalicious commit - resolvedcritical
Malicious code in dxr-dos (npm)
The npm package dxr-dos contains malicious code that executes arbitrary code via a mutable third-party dependency (deathoffather-project) and extracts a hidden PHP C2 panel from a password-protected archive. The package is advertised as a DDoS toolkit with command-and-control capabilities.
npmCompromised packageMalicious commit