{"id":168397,"date":"2026-08-21T00:45:34","date_gmt":"2026-08-21T00:45:34","guid":{"rendered":"https:\/\/crypto-economy.com\/es\/?p=168397"},"modified":"2026-08-21T00:45:37","modified_gmt":"2026-08-21T00:45:37","slug":"sospechan-de-hackers-norcoreanos-en-un-ataque-a-la-cadena-de-suministro-de-rust-dirigido-a-arrayref","status":"publish","type":"post","link":"https:\/\/crypto-economy.com\/es\/sospechan-de-hackers-norcoreanos-en-un-ataque-a-la-cadena-de-suministro-de-rust-dirigido-a-arrayref\/","title":{"rendered":"Sospechan de hackers norcoreanos en un ataque a la cadena de suministro de Rust dirigido a Arrayref\u00a0"},"content":{"rendered":"<p><span style=\"font-weight: 400\">Puntos Clave de la Noticia:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><b>Paquetes afectados:<\/b><span style=\"font-weight: 400\"> Versiones maliciosas de las crates de Rust <\/span><span style=\"font-weight: 400\">arrayref<\/span><span style=\"font-weight: 400\"> (@0.3.10), append-only-vec (@0.1.9) e internment (@0.8.7) fueron publicadas en crates.io el 20 de agosto de 2026.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Alcance de la librer\u00eda:<\/b><span style=\"font-weight: 400\"> La crate arrayref registra m\u00e1s de 244 millones de descargas acumuladas y se encuentra presente en tres cuartas partes de los entornos donde opera Rust.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Respuesta de seguridad:<\/b><span style=\"font-weight: 400\"> El Rust Security Response Team elimin\u00f3 los paquetes comprometidos tras permanecer activos entre 86 y 107 minutos en el repositorio oficial.<\/span><\/li>\n<\/ul>\n<hr \/>\n<p><span style=\"font-weight: 400\">Investigadores de <a href=\"https:\/\/crypto-economy.com\/es\/coti-elige-la-experiencia-en-ciberseguridad-de-sayfer-tras-proteger-miles-de-millones-para-los-principales-clientes-web3\/\" target=\"_blank\" rel=\"noopener\">ciberseguridad<\/a> identificaron la presunta participaci\u00f3n de <\/span><b>hackers norcoreanos en un ataque a la cadena de suministro de <a href=\"http:\/\/TL;DR: Affected packages: Malicious versions of the Rust crates arrayref (@0.3.10), append-only-vec (@0.1.9), and internment (@0.8.7) were published on crates.io on August 20, 2026. Library scope: The arrayref crate accounts for over 244 million cumulative downloads and is present across three-quarters of environments where Rust operates. Security response: The Rust Security Response Team removed the compromised packages after they remained active for 86 to 107 minutes on the official registry. Cybersecurity researchers identified the suspected involvement of North Korean hackers in a Rust supply chain attack targeting Arrayref and other critical dependencies on Thursday, August 20. The attack vector originated after the credentials or the machine of the project&apos;s legitimate maintainer were compromised. Leveraging this unauthorized access, the attackers uploaded tampered versions that introduced a dependency on a malicious package named proc-macro1. The build script (build.rs) executed malicious code during the software packaging process. According to a technical analysis published by the security firm Aikido, the compiled payload integrated functions designed to extract browser credentials and access the local storage of crypto wallet extensions. Infrastructure links to state-sponsored cyber espionage campaigns The Wiz Threat Intelligence team reported significant technical overlaps between the servers used in this attack and previous campaigns attributed to the Pyongyang regime. The command and control (C2) infrastructure utilized IP address ranges associated with hosting provider Hostwinds LLC. Data from Wiz indicates that these same addresses had previously appeared in reports from Google Cloud Threat Intelligence and Mandiant linked to the advanced persistent threat group UNC1069, an actor associated with offensive campaigns against open-source ecosystems like npm. The report suggests that state-sponsored actors may be expanding their tactical vectors toward low-level dependencies in Rust to compromise targets within the digital asset industry and corporate development environments. The operational response from repository administrators mitigated initial exposure. The Rust Security Response Team revoked the contaminated packages and temporarily locked the developer&apos;s account as a precautionary measure. The compromised version of arrayref remained available for 86 minutes before being removed from the official crates.io indices. Cybersecurity teams and repository administrators are actively reviewing Cargo.lock files to verify the absence of dependencies on proc-macro1, proc-macro-en, or unauthenticated versions in local builds. The Rust Security Team will continue publishing technical updates as the forensic audit into the compromised credentials progresses.\" target=\"_blank\" rel=\"noopener\">Rust<\/a> dirigido a Arrayref<\/b><span style=\"font-weight: 400\"> y otras dependencias cr\u00edticas durante la jornada del jueves\u00a0 20 de agosto.<\/span><\/p>\n<p><!--more--><\/p>\n<p><span style=\"font-weight: 400\">El vector de ataque se origin\u00f3 tras el compromiso de las credenciales o del equipo del mantenedor leg\u00edtimo del proyecto. A partir de este acceso no autorizado, l<\/span><b>os atacantes cargaron versiones adulteradas<\/b><span style=\"font-weight: 400\"> que introduc\u00edan una dependencia hacia un paquete malicioso denominado <\/span><b>proc-macro1.<\/b><\/p>\n<p><span style=\"font-weight: 400\">El script de compilaci\u00f3n (build.rs) ejecutaba c\u00f3digo malicioso durante el proceso de empaquetado del software. Seg\u00fan el an\u00e1lisis t\u00e9cnico publicado por la firma de seguridad Aikido, el payload compilado integraba funciones destinadas a extraer credenciales de navegadores y acceder al almacenamiento de extensiones de <\/span><b><a href=\"https:\/\/crypto-economy.com\/es\/un-error-de-codigo-de-hace-12-anos-golpea-a-las-billeteras-cripto-web-y-cuesta-57-millones-a-los-inversores\/\" target=\"_blank\" rel=\"noopener\">billeteras cripto<\/a>.<\/b><\/p>\n<h2><b>Nexos de infraestructura con campa\u00f1as estatales de ciberespionaje<\/b><\/h2>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-168398 size-full\" src=\"https:\/\/crypto-economy.com\/es\/\/wp-content\/uploads\/sites\/4\/2026\/08\/hackers-norcoreanos-Arrayref1-.jpg\" alt=\"hackers norcoreanos - Arrayref\" width=\"1024\" height=\"300\" srcset=\"https:\/\/crypto-economy.com\/es\/\/wp-content\/uploads\/sites\/4\/2026\/08\/hackers-norcoreanos-Arrayref1-.jpg 1024w, https:\/\/crypto-economy.com\/es\/\/wp-content\/uploads\/sites\/4\/2026\/08\/hackers-norcoreanos-Arrayref1--300x88.jpg 300w, https:\/\/crypto-economy.com\/es\/\/wp-content\/uploads\/sites\/4\/2026\/08\/hackers-norcoreanos-Arrayref1--768x225.jpg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p><span style=\"font-weight: 400\">El equipo de inteligencia de amenazas de <\/span><b>Wiz <\/b><span style=\"font-weight: 400\">report\u00f3 coincidencias t\u00e9cnicas significativas entre los servidores empleados en este ataque y campa\u00f1as previas atribuidas al r\u00e9gimen de Pionyang.<\/span><b> La infraestructura de comando y control (C2) utiliz\u00f3 rangos de direcciones IP asociados con el proveedor Hostwinds LLC.<\/b><\/p>\n<p><span style=\"font-weight: 400\">Datos de Wiz se\u00f1alan que estas mismas direcciones figuraron previamente en reportes de <\/span><b>Google Cloud Threat Intelligence<\/b><span style=\"font-weight: 400\"> y <\/span><b>Mandiant<\/b><span style=\"font-weight: 400\"> vinculados al grupo de amenazas persistentes UNC1069, actor asociado a ofensivas contra ecosistemas de c\u00f3digo abierto como npm. El reporte sugiere que los actores estatales podr\u00edan estar expandiendo sus vectores t\u00e1cticos hacia dependencias de bajo nivel en Rust con el prop\u00f3sito de alcanzar objetivos dentro de la industria de activos digitales y el desarrollo corporativo.<\/span><\/p>\n<p><span style=\"font-weight: 400\">La respuesta operativa de los administradores del repositorio mitig\u00f3 la exposici\u00f3n inicial. El <\/span><b>Rust Security Response Team<\/b><span style=\"font-weight: 400\"> procedi\u00f3 a revocar los paquetes contaminados y a bloquear temporalmente la cuenta del desarrollador como medida preventiva. La versi\u00f3n comprometida de arrayref permaneci\u00f3 disponible durante 86 minutos antes de ser retirada de los \u00edndices oficiales de crates.io.<\/span><\/p>\n<p><b>Equipos de ciberseguridad y administradores de repositorios mantienen revisiones activas sobre los archivos Cargo.lock<\/b><span style=\"font-weight: 400\"> para verificar la ausencia de dependencias hacia los paquetes proc-macro1, proc-macro-en o versiones no autenticadas en compilaciones locales. El equipo de seguridad de Rust continuar\u00e1 la publicaci\u00f3n de actualizaciones t\u00e9cnicas a medida que avance la auditor\u00eda forense sobre las credenciales comprometidas.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Puntos Clave de la Noticia: Paquetes afectados: Versiones maliciosas de las crates de Rust arrayref (@0.3.10), append-only-vec (@0.1.9) e internment (@0.8.7) fueron publicadas en crates.io el 20 de agosto de 2026. Alcance de la librer\u00eda: La crate arrayref registra m\u00e1s de 244 millones de descargas acumuladas y se encuentra presente en tres cuartas partes de &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Sospechan de hackers norcoreanos en un ataque a la cadena de suministro de Rust dirigido a Arrayref\u00a0\" class=\"read-more button\" href=\"https:\/\/crypto-economy.com\/es\/sospechan-de-hackers-norcoreanos-en-un-ataque-a-la-cadena-de-suministro-de-rust-dirigido-a-arrayref\/#more-168397\" aria-label=\"Leer m\u00e1s sobre Sospechan de hackers norcoreanos en un ataque a la cadena de suministro de Rust dirigido a Arrayref\u00a0\">Leer m\u00e1s<\/a><\/p>\n","protected":false},"author":48,"featured_media":168399,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_title":"","rank_math_description":"Investigadores de seguridad detectaron versiones maliciosas de las librer\u00edas Rust arrayref y append-only-vec vinculadas a t\u00e1cticas atribuidas a Corea del Norte.\n","footnotes":""},"categories":[971],"tags":[9596,7113,9595],"class_list":["post-168397","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-noticias","tag-arrayref","tag-hackers-norcoreanos","tag-rust"],"_links":{"self":[{"href":"https:\/\/crypto-economy.com\/es\/wp-json\/wp\/v2\/posts\/168397","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/crypto-economy.com\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crypto-economy.com\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crypto-economy.com\/es\/wp-json\/wp\/v2\/users\/48"}],"replies":[{"embeddable":true,"href":"https:\/\/crypto-economy.com\/es\/wp-json\/wp\/v2\/comments?post=168397"}],"version-history":[{"count":1,"href":"https:\/\/crypto-economy.com\/es\/wp-json\/wp\/v2\/posts\/168397\/revisions"}],"predecessor-version":[{"id":168400,"href":"https:\/\/crypto-economy.com\/es\/wp-json\/wp\/v2\/posts\/168397\/revisions\/168400"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crypto-economy.com\/es\/wp-json\/wp\/v2\/media\/168399"}],"wp:attachment":[{"href":"https:\/\/crypto-economy.com\/es\/wp-json\/wp\/v2\/media?parent=168397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crypto-economy.com\/es\/wp-json\/wp\/v2\/categories?post=168397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crypto-economy.com\/es\/wp-json\/wp\/v2\/tags?post=168397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}