Be alert: targeted attacks on prominent Rustaceans
crates.io security team warns of an ongoing social engineering campaign targeting Rust crate maintainers via fake video calls to steal accounts and publish malware.
The crates.io security team and Adam Harvey warn of an active campaign targeting rust-lang members and owners of popular crates. Attackers lure targets with video calls offering jobs, projects, or contracts, then trick them into installing a purportedly missing audio codec or executing a command placed on the clipboard. The goal is to compromise devices and maintainer accounts in order to publish malware to the crates.io ecosystem.
- Ongoing campaign targets rust-lang members and popular crate owners
- Video call lures pose as job, project, or contract opportunities
- Victims prompted to install a fake missing audio codec or run clipboard commands
- Objective is compromising devices and accounts to publish malware
- Public warning issued by the crates security team
Be alert: targeted attacks on prominent Rustaceans Important warning from Adam Harvey and the crates security team: We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware. A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard). Last month this trick was used in a…
This source does not provide full text. Read it at simonwillison.net.