August 22, 2026
- The poisoned
arrayrefRust crate is now linked to North Korean actors. Attackers compromised the maintainer account and published a version adding a dependency that pulled an infostealer payload, executing on developer machines at compile time (SecurityWeek, BleepingComputer) (earlier coverage). · Supply Chain - Two more malicious Rust crates impersonating
proc-macro2were caught by Nextron's artifact scanner, suggesting the crates.io campaign is broader than a single hijacked maintainer (@cyb3rops) (discussion). · Supply Chain
in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight