
North Korean Hackers Suspected in Rust Supply Chain Attack Targeting Arrayref
TL;DR: Affected packages: Malicious versions of the Rust crates arrayref (@0.3.10), append-only-vec (@0.1.9), and internment (@0.8.7) were published on crates.io on August 20, 2026. Library scope: