Original Title and Summary

Original Title and Summary

The arrayref Rust crate vulnerability (CVE-2022-23344) has been linked to a significant supply chain attack, putting thousands of projects at risk.

Bottom Line: The arrayref Rust crate vulnerability (CVE-2022-23344) has been linked to a significant supply chain attack, putting thousands of projects at risk.

What's Happening: The malicious versions of arrayref and other Rust crates were used to execute a backdoor at compile time, with the compromised infrastructure overlapping with recent supply chain attacks attributed to North Korea (DPRK), including the Mastra and axios campaigns. These attacks targeted multiple projects worldwide, with thousands of affected projects identified so far.

What to Do: Security teams should verify the integrity of their Rust dependencies and ensure that all dependencies are up-to-date with the latest security patches. Immediate action is required to prevent potential exploitation of this vulnerability.

Source: Wiz Blog