---
title: "Be alert: targeted attacks on prominent Rustaceans"
slug: be-alert-targeted-attacks-on-prominent-rustaceans
url: https://listedarticles.com/articles/be-alert-targeted-attacks-on-prominent-rustaceans
canonical_url: https://blog.rust-lang.org/2026/09/17/targeted-attacks/
content_type: announcement
language: en
published_at: 2026-09-17T12:00:00.000Z
updated_at: 2026-09-19T00:10:00.224Z
author: "Rust Security Response Working Group"
authored_by: human
publisher: "Rust Blog"
publisher_url: https://blog.rust-lang.org/
topics: ["Security", "Rust", "Open Source"]
license: all-rights-reserved
word_count: 276
reading_minutes: 1
citation: "Rust Security Response Working Group, Rust Blog. \"Be alert: targeted attacks on prominent Rustaceans.\" 17 Sept 2026. https://blog.rust-lang.org/2026/09/17/targeted-attacks/ (all-rights-reserved)"
# The full text follows. The web page shows an extract and sends readers
# to the source above; quote the citation and link the canonical URL.
---

# Be alert: targeted attacks on prominent Rustaceans

> We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware. A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard).

We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware.

## 

A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard).

These attackers are setting up new but legitimate seeming company profiles, including plausible LinkedIn presences, in order to pass cursory inspection.

A [previous attack of this form](https://grack.com/blog/2026/06/25/dissecting-a-failed-nation-state-attack/) targeted many prominent Rust developers in
June, and, last month, the [`arrayref` crate was briefly compromised through similar
attacks](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/). At this moment we do not know if these are all a part of the same
campaign.

This attack style is [known to be used by the DPRK](https://kudelskisecurity.com/research/how-dprks-contagious-interview-campaign-targets-developers), and has been [seen outside of the Rust community as well](https://ashishb.net/security/contagious-interview/).

## 

Please take extra care in the near term. Be appropriately suspicious of cold outreaches, and ensure that any calls you have with new people are on platforms you trust — ideally, try to be the one who sets up the call on a platform you already use.

Please also re-check that your accounts look normal: MFA enabled, no unexpected logins on platforms that can track that, and so on.

If you have any concerns about your accounts, please reach out to
[help@crates.io](mailto:help@crates.io) (for crates.io account concerns) and/or
[security@rust-lang.org](mailto:security@rust-lang.org) (for any other
concerns). We're very happy to help.
