Rust Foundation Library arrayref Hit by Supply Chain Attack, Exposing Credentials of Vast Developer Ecosystem

A supply chain attack targeted three popular Rust crates, including the foundational arrayref library used by ~75% of Rust environments. The malicious update secretly steals credentials during compilation, with ties to North Korean hacking groups. Widely used in Solana and Ethereum toolchains, the tainted packages were downloaded extensively before removal 86 minutes later.

Read More