Rust crate owners warned of fake job-interview malware
The Rust project warns fake interviews push remote-access malware at crate owners, while outlets disagree on North Korean ties and theft figures.
The Rust project has warned that attackers are targeting Rust-lang team members, contributors, and popular crate owners with fake recruiter interviews and video calls backed by plausible company profiles and LinkedIn presences. Victims are pressed to install purportedly missing audio codecs or execute clipboard-planted commands that deliver a remote access trojan, with the aim of compromising devices and accounts and potentially spreading malware through crates.io. SecurityWeek calls the campaign linked to North Korean threat actors and says crates were previously compromised, while The Register, citing security engineer Adam Harvey, says the tactics resemble DPRK fake-recruiter operations and ties the warning to a June attempt on a crates.io maintainer and an August attack through malicious arrayref versions. Help Net Security goes further by naming the North Korean group Contagious Interview, also known as WaterPlum, and adding malicious coding assignments plus use of stolen credentials for cryptocurrency theft, extortion, and North Korean IT-worker schemes. The outlets also disagree on impact totals: The Register cites a four-nation advisory attributing more than 30,000 compromised devices and over $10 million stolen to such DPRK operations, whereas Help Net Security says the group infected over 30,000 devices across more than 100 countries and stole from over 7,000 cryptocurrency wallets. Defenders are urged to verify contacts, use trusted platforms, and enable multi-factor authentication.
- The Rust project warns of an ongoing campaign using fake job interviews and video calls against Rust-lang team members, contributors, and popular crate owners.
- Attackers use plausible fake company profiles and LinkedIn presences, then push purportedly missing audio codecs or clipboard-planted commands that deliver a remote access trojan.
- The stated aim is to compromise devices and accounts and potentially distribute malware through the crates.io ecosystem.
- Attribution differs: Adam Harvey, cited by The Register, says the tactics resemble DPRK fake-recruiter campaigns; SecurityWeek says the campaign is linked to North Korean actors; Help Net Security names state-sponsored Contagious…
- The Register says the warning follows a June fake-interview attempt on a crates.io maintainer and an August supply-chain attack via malicious arrayref crate versions; SecurityWeek says crates were previously compromised.
- Scale figures disagree: a four-nation advisory cited by The Register attributes more than 30,000 compromised devices and over $10 million stolen to such DPRK operations, while Help Net Security reports over 30,000 devices in more than 100…
- Help Net Security also describes malicious coding assignments and says stolen credentials are used for cryptocurrency theft, extortion, and North Korean IT-worker schemes.
- Defenders are urged to verify contacts, use trusted platforms, and enable multi-factor authentication.
Coverage timelineoldest first · each row is one article
- · 5d agoRustaceans warned of job interviews with a malicious payload
The Register · Security· 62
Rust project warns attackers use fake recruiter interviews targeting crate owners to deploy RATs and compromise the package ecosystem.
- · 5d agoRust Team Members and Popular Crate Owners Targeted via Video Calls
SecurityWeek· 65
A social engineering campaign targets Rust developers via video calls to steal credentials and deploy malicious packages.
- · 5d agoNorth Korea’s job interview scam runs both ways
Help Net Security· 68