{"article":{"slug":"be-alert-targeted-attacks-on-prominent-rustaceans","title":"Be alert: targeted attacks on prominent Rustaceans","subtitle":null,"summary":"We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware. A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard).","content_type":"announcement","language":"en","canonical_url":"https://blog.rust-lang.org/2026/09/17/targeted-attacks/","author":{"name":"Rust Security Response Working Group","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Rust Blog","url":"https://blog.rust-lang.org/","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Rust","slug":"rust","url":"https://listedarticles.com/topics/rust"},{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":276,"reading_minutes":1,"published_at":"2026-09-17T12:00:00.000Z","added_at":"2026-09-19T00:10:00.224Z","updated_at":"2026-09-19T00:10:00.224Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/be-alert-targeted-attacks-on-prominent-rustaceans","markdown_url":"https://listedarticles.com/articles/be-alert-targeted-attacks-on-prominent-rustaceans.md","example":false,"citation":"Rust Security Response Working Group, Rust Blog. \"Be alert: targeted attacks on prominent Rustaceans.\" 17 Sept 2026. https://blog.rust-lang.org/2026/09/17/targeted-attacks/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://blog.rust-lang.org/2026/09/17/targeted-attacks/"},"body_markdown":"We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware.\n\n## \n\nA video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard).\n\nThese attackers are setting up new but legitimate seeming company profiles, including plausible LinkedIn presences, in order to pass cursory inspection.\n\nA [previous attack of this form](https://grack.com/blog/2026/06/25/dissecting-a-failed-nation-state-attack/) targeted many prominent Rust developers in\nJune, and, last month, the [`arrayref` crate was briefly compromised through similar\nattacks](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/). At this moment we do not know if these are all a part of the same\ncampaign.\n\nThis attack style is [known to be used by the DPRK](https://kudelskisecurity.com/research/how-dprks-contagious-interview-campaign-targets-developers), and has been [seen outside of the Rust community as well](https://ashishb.net/security/contagious-interview/).\n\n## \n\nPlease take extra care in the near term. Be appropriately suspicious of cold outreaches, and ensure that any calls you have with new people are on platforms you trust — ideally, try to be the one who sets up the call on a platform you already use.\n\nPlease also re-check that your accounts look normal: MFA enabled, no unexpected logins on platforms that can track that, and so on.\n\nIf you have any concerns about your accounts, please reach out to\n[help@crates.io](mailto:help@crates.io) (for crates.io account concerns) and/or\n[security@rust-lang.org](mailto:security@rust-lang.org) (for any other\nconcerns). We're very happy to help.","body_html":"<p>We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware.</p>\n<p>## </p>\n<p>A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that&#39;s used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard).</p>\n<p>These attackers are setting up new but legitimate seeming company profiles, including plausible LinkedIn presences, in order to pass cursory inspection.</p>\n<p>A <a href=\"https://grack.com/blog/2026/06/25/dissecting-a-failed-nation-state-attack/\" rel=\"nofollow ugc noopener\">previous attack of this form</a> targeted many prominent Rust developers in\nJune, and, last month, the <a href=\"https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/\" rel=\"nofollow ugc noopener\"><code>arrayref</code> crate was briefly compromised through similar\nattacks</a>. At this moment we do not know if these are all a part of the same\ncampaign.</p>\n<p>This attack style is <a href=\"https://kudelskisecurity.com/research/how-dprks-contagious-interview-campaign-targets-developers\" rel=\"nofollow ugc noopener\">known to be used by the DPRK</a>, and has been <a href=\"https://ashishb.net/security/contagious-interview/\" rel=\"nofollow ugc noopener\">seen outside of the Rust community as well</a>.</p>\n<p>## </p>\n<p>Please take extra care in the near term. Be appropriately suspicious of cold outreaches, and ensure that any calls you have with new people are on platforms you trust — ideally, try to be the one who sets up the call on a platform you already use.</p>\n<p>Please also re-check that your accounts look normal: MFA enabled, no unexpected logins on platforms that can track that, and so on.</p>\n<p>If you have any concerns about your accounts, please reach out to\n<a href=\"mailto:help@crates.io\">help@crates.io</a> (for crates.io account concerns) and/or\n<a href=\"mailto:security@rust-lang.org\">security@rust-lang.org</a> (for any other\nconcerns). We&#39;re very happy to help.</p>","headings":[]}}