Mark RadarMARK RADAR
About
EN
Sign in

Malicious ArrayRef Package Hits Solana and Ethereum Developers

3 reports · First detected 2026-08-21 · Last active 2026-08-24

ArrayRef is a widely used Rust package embedded in dependency chains across blockchain development, including tooling for Solana and Ethereum. Its compromise underscores the reach of software supply-chain attacks: tampering with a small, trusted component can expose developers and projects far beyond the original repository, particularly when malicious code executes as part of a routine build process.

Recent security disclosures found that the compromised ArrayRef package used a dependency-linked build script to load a malicious payload when developers compiled their projects. The malware was designed to steal browser login credentials, turning an ordinary build into a credential-theft vector. Researchers said technical indicators resembled operations associated with BlueNoroff, a North Korea-linked hacking group, though the attribution has not been independently confirmed.

All Coverage

3 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)