Be alert: targeted attacks on prominent Rustaceans
Ongoing social engineering campaign targets Rust maintainers via fake recruiters and video calls to compromise accounts and publish malicious crates.
The Rust project warns of an ongoing targeted campaign against rust-lang members and owners of popular crates, aiming to compromise devices and accounts to publish malware through the ecosystem. Attackers schedule video calls under positive pretexts such as jobs or contracts, using newly created but plausible-looking company profiles and LinkedIn presences to appear legitimate. Victims are persuaded to install purportedly missing audio codecs or execute commands, for example via a command placed on the clipboard. The Rust team urges verifying calls on trusted platforms, enabling MFA, checking for unexpected logins, and reporting concerns to help@crates.io or security@rust-lang.org.