North Korean-linked actors compromised arrayref, internment, and append-only-vec on crates.io, injecting a build-time infostealer that harvested browser and crypto credentials from millions of potential downloads. The malicious versions lived less than two hours, yet the attack highlights deepening state-sponsored interest in Rust supply chains. Defenders must now audit lockfiles and build processes with fresh urgency.