Rust Team Members and Popular Crate Owners Targeted via Video Calls
A social engineering campaign targets Rust developers via video calls to steal credentials and deploy malicious packages.
An ongoing social engineering campaign targets Rust-lang team members and popular crate owners via video calls. Attackers lure targets with job offers, then trick them into installing malicious software or executing clipboard code. The campaign is linked to North Korean threat actors and has previously compromised crates.
- Attackers lure Rust developers into video calls under false job offers to hijack credentials.
- Malicious code is delivered via clipboard paste or fake software under the pretext of a missing audio codec.
- The campaign is linked to North Korean threat actors and prior incidents targeting Rust developers.
- Defenders are urged to verify contacts, use trusted platforms, and enable multi-factor authentication.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | crates.io | ck developer credentials and deploy malicious packages. The crates.io team and the security response working group issued the war |
Full article330 words · extracted from securityweek.com · click to collapse
The Rust project warned last week that an ongoing social engineering campaign is targeting Rust-lang team members and the owners of popular crates to hijack developer credentials and deploy malicious packages.
The crates.io team and the security response working group issued the warning. According to the alert, attackers lure targets into video calls under the guise of job offers or contract opportunities.
Once on the call, the target is tricked into installing software under the pretext of a missing audio codec or executing malicious code pasted to their clipboard.
To lend the approach credibility, the attackers are creating new companies with LinkedIn pages convincing enough to pass a quick look.
The Rust team connected the campaign to two earlier incidents. Many prominent Rust developers were targeted in a similar attack in June, and the arrayref crate was compromised for a short time in August through what the team described as similar attacks. It said it does not know whether all of these incidents are part of the same campaign.
SecurityWeek previously reported on the arrayref incident, which surfaced on August 20 and was linked to North Korean threat actors. The attackers had compromised the account of arrayref’s developer and published several malicious crates.
Advertisement. Scroll to continue reading.
In the new alert, the Rust team noted that North Korea is known to use this style of attack, which has also been seen outside the Rust community. It did not name a specific actor behind the current activity.
Developers have been urged to be wary of unsolicited approaches and to hold calls with new contacts on platforms they trust, preferably one they set up themselves. They should also check their accounts for anything unusual, ensure multi-factor authentication is enabled, and confirm there are no unrecognized logins.
Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages
Related: Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
Related: Multiple Jscrambler Packages Impacted by Supply Chain Attack
Text extracted automatically; images, tables and formatting may be missing. Original: