Rust Team Members and Popular Crate Owners Targeted via Video Calls
Rust project members and popular crate owners targeted via video calls for credential theft.
Summary
The Rust project has warned of a social engineering campaign targeting its team members and popular crate owners. Attackers use fake job offers in video calls to trick victims into installing malicious software or executing code. This campaign shares similarities with previous attacks linked to North Korean threat actors, though a direct link to ongoing campaigns is unconfirmed.
Full text
The Rust project warned last week that an ongoing social engineering campaign is targeting Rust-lang team members and the owners of popular crates to hijack developer credentials and deploy malicious packages. The crates.io team and the security response working group issued the warning. According to the alert, attackers lure targets into video calls under the guise of job offers or contract opportunities. Once on the call, the target is tricked into installing software under the pretext of a missing audio codec or executing malicious code pasted to their clipboard. To lend the approach credibility, the attackers are creating new companies with LinkedIn pages convincing enough to pass a quick look. The Rust team connected the campaign to two earlier incidents. Many prominent Rust developers were targeted in a similar attack in June, and the arrayref crate was compromised for a short time in August through what the team described as similar attacks. It said it does not know whether all of these incidents are part of the same campaign. SecurityWeek previously reported on the arrayref incident, which surfaced on August 20 and was linked to North Korean threat actors. The attackers had compromised the account of arrayref’s developer and published several malicious crates. Advertisement. Scroll to continue reading. In the new alert, the Rust team noted that North Korea is known to use this style of attack, which has also been seen outside the Rust community. It did not name a specific actor behind the current activity. Developers have been urged to be wary of unsolicited approaches and to hold calls with new contacts on platforms they trust, preferably one they set up themselves. They should also check their accounts for anything unusual, ensure multi-factor authentication is enabled, and confirm there are no unrecognized logins. Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Related: Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack Related: Multiple Jscrambler Packages Impacted by Supply Chain Attack Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Microsoft Patches 18 Vulnerabilities in AI, Cloud ProductsCheck Point, Kaspersky, Tanium Patch Product VulnerabilitiesCyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board VesselsOpenAI Says Its Models Searched GitHub for Leaked API Keys During TrainingCISA Retires Weekly Vulnerability Bulletin in Risk-Based PivotAI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing RefusalsPixel Modem Zero-Day Exploited in Targeted AttacksUS, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware Latest News CrowdSec Confirms Source Code Stolen in Supply Chain AttackColorado Water Utilities Hit by Cyberattacks Targeting OT SystemsOrganizations Warned of 3 Exploited Linux Kernel VulnerabilitiesGoogle Confirms Gemini AI Breached Three FirmsTigerByte Cyber Emerges From Stealth With $3 Million in FundingIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawAI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code23 Million User Records Compromised in Gyazo Data Breach Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email