Malicious ArrayRef Package Hits Solana and Ethereum Developers
ArrayRef is a widely used Rust package embedded in dependency chains across blockchain development, including tooling for Solana and Ethereum. Its compromise underscores the reach of software supply-chain attacks: tampering with a small, trusted component can expose developers and projects far beyond the original repository, particularly when malicious code executes as part of a routine build process.
Recent security disclosures found that the compromised ArrayRef package used a dependency-linked build script to load a malicious payload when developers compiled their projects. The malware was designed to steal browser login credentials, turning an ordinary build into a credential-theft vector. Researchers said technical indicators resembled operations associated with BlueNoroff, a North Korea-linked hacking group, though the attribution has not been independently confirmed.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →