Wiz published analysis on August 20 of malicious Rust packages that could run a backdoor when a project was compiled. The affected versions were arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9.

The Rust Security Response Team confirmed the malicious dependencies, removed the affected versions from crates.io and locked the maintainer’s account. It said the maintainer’s computer or credentials were likely compromised. The initial report came from Nextron Systems, rather than Wiz.

Wiz analyzed the payload and identified infrastructure overlaps with previously reported North Korean campaigns; that is an attribution assessment, not proof of responsibility. Developers should consult the Rust advisory to check cached dependencies and determine whether their build environments used the affected packages.

Sources

About Pituchim · Report a correction

Share this story

LinkedIn X Facebook WhatsApp Telegram Reddit Email