Fake recruiters call Rust maintainers to plant malware on their Macs

Fake recruiters are booking video calls with Rust maintainers and pushing malware.

CSBadmin
2 Min Read

The Rust project’s crates.io team and security response working group have warned that an ongoing social engineering campaign is targeting Rust-lang team members and the owners of popular crates.

The pattern is a fake recruiter. Attackers arrange a video call framed as a job, contract, or project opportunity, then push the target to install software presented as a missing audio codec, or to paste a command from the clipboard. New company profiles with plausible LinkedIn pages are built to survive a quick check.

The technique is simple rather than exotic, and it matches the fake-interview playbook attributed to North Korean operators. A recent advisory from Australia, Germany, Japan, and the United States said that activity compromised more than 30,000 devices and pulled in over $10M.

The team tied the alert to two earlier incidents. In June, Rust developers were approached by what looked like a Singaporean venture capital firm; maintainer Matt Mastracci found the business was defunct but said the approach nearly infected his machine with a remote access trojan. In August, malicious versions of the arrayref crate – 245 million lifetime downloads – shipped for under two hours after a maintainer’s credentials were apparently compromised.

What maintainers should do

Unsolicited approaches deserve scrutiny even when the sender looks legitimate. Hold calls on a platform you choose, enable multi-factor authentication, review account logins, and check for unfamiliar sessions. Package ecosystems inherit the security of their maintainers’ laptops.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.