North Korean Supply Chain Attack Targets Rust Ecosystem
🔒 Wiz researchers linked a recent supply chain attack in the Rust ecosystem to state-sponsored North Korean actors. The campaign compromised maintainer accounts on crates.io to alter manifests and import a typosquatted dependency, allowing malicious build-time code to run during compilation. The backdoor aimed to harvest browser credentials, crypto wallets and developer secrets, affecting widely used crates including arrayref, internment and append-only-vec.
