The Rust project’s crates.io team and security response working group have warned that an ongoing social engineering campaign is targeting Rust-lang team members and the owners of popular crates.
The pattern is a fake recruiter. Attackers arrange a video call framed as a job, contract, or project opportunity, then push the target to install software presented as a missing audio codec, or to paste a command from the clipboard. New company profiles with plausible LinkedIn pages are built to survive a quick check.
The technique is simple rather than exotic, and it matches the fake-interview playbook attributed to North Korean operators. A recent advisory from Australia, Germany, Japan, and the United States said that activity compromised more than 30,000 devices and pulled in over $10M.
The team tied the alert to two earlier incidents. In June, Rust developers were approached by what looked like a Singaporean venture capital firm; maintainer Matt Mastracci found the business was defunct but said the approach nearly infected his machine with a remote access trojan. In August, malicious versions of the arrayref crate – 245 million lifetime downloads – shipped for under two hours after a maintainer’s credentials were apparently compromised.
What maintainers should do
Unsolicited approaches deserve scrutiny even when the sender looks legitimate. Hold calls on a platform you choose, enable multi-factor authentication, review account logins, and check for unfamiliar sessions. Package ecosystems inherit the security of their maintainers’ laptops.
