Rust supply chain attack linked to North Korean hackers

Rust supply chain attack linked to North Korean hackers

North Korean hackers are responsible for a new open source software (OSS) supply chain attack targeting the Rust ecosystem, cybersecurity firm Wiz reports.

The attack occurred on August 20th and affected one of the most popular Rust crates, arrayrefan array conversion utility with over 245 million downloads that is found in approximately 75% of environments where Rust is used.

The malicious package version (email protected) was pushed to crates.io from the legitimate maintainer’s account. About 20 minutes later, poisoned versions of internment And append-only-vectwo boxes from the same owner were also released.

These packages as well as boxes in the possession of the attacker (aovine, arone, aroneao, tinymember), pointed to the same malicious dependency, (email protected)who claimed to be legitimate proc-macro2 Package.

Within the dependency, the threat actor hid a malicious file. build.rsdesigned to retrieve a platform-specific second-stage binary over TLS after certificate validation is disabled.

The Rust Security Response Team removed the malicious packages approximately 86 minutes later. affirmative The compromise: “A new version of the Arrayref crate was released with a direct dependency on proc-macro1 that would execute a malicious build script.”

Advertising. Scroll to continue reading.

Shortly afterwards, the Rust security team said All malicious packages have been removed and the clean iterations have been restored. The team found no evidence of actual use of the malicious boxes.

“We do not believe the author of arrayref is acting maliciously, but his computer or credentials are likely compromised and we are attempting to contact him,” Rust’s security team said.

StepSecurityAnalysis of the attack shows that the threat actor planned each step precisely, creating typo-filled versions of proc-macro2 and an impersonation account shortly before releasing the poisoned Arrayref version.

Accordingly wizardNorth Korean threat actor Sapphire Sleet, which carried out the attacks on Axios and Mastra NPM supply chains in April and June, was likely responsible for the Arrayref incident due to significant infrastructure overlap.

The Arrayref payloads signal an endpoint used in the Mastra attack, the command-and-control (C&C) traffic was recorded on an IP used in the Axios campaign, and the same Hostwinds LLC infrastructure IP range was used in all three incidents.

Related: Fortune 500 companies affected by Azure data theft campaign

Related: Trivy, not LiteLLM behind the 2,500 organization compromise

Related: Hackers are targeting Zimbra servers as part of an active exploitation campaign

Related: AmnesiaStealer macOS malware steals data and controls browser sessions

Leave a Reply

Your email address will not be published. Required fields are marked *