The Rust project has warned that attackers are actively targeting prominent community members and maintainers of popular crates.io packages in an apparent effort to compromise accounts and publish malware through trusted Rust crates. The attackers use credible-looking fictitious company websites and LinkedIn profiles to approach targets with seemingly legitimate job, project, or contract opportunities and arrange video calls.
During the calls, the operators pressure targets to install a supposed missing audio codec or run commands, including commands copied through the clipboard, to gain access to devices or maintainer accounts. Rust advised maintainers to treat unsolicited outreach with skepticism, use trusted conferencing platforms, and review MFA and account-login activity; reporting has linked the tactic to prior DPRK-associated activity, including the brief compromise of the arrayref crate, though attribution for the current campaign is unconfirmed.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
The crates.io team and Rust security working group issued an alert about an ongoing social-engineering campaign targeting rust-lang members and maintainers of popular crates. Attackers used credible company and LinkedIn profiles to arrange fraudulent calls, then tried to induce targets to install a purported audio codec or execute clipboard-delivered commands to compromise accounts and publish malware through crates.
The arrayref crate was briefly compromised in the month preceding the September alert through attacks described as similar to the current social-engineering activity. Rust stated it could not determine whether the incidents were part of the same campaign.
Similar attacks reportedly targeted numerous Rust developers in June, using an attack style later associated with the current activity. The source does not specify the year.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.