Rust Team Members and Popular Crate Owners Targeted via Video Calls

https://www.securityweek.com/wp-content/uploads/2025/01/application-security-vulnerabilities.jpeg

The Rust project warned last week that an ongoing social engineering campaign is targeting Rust-lang team members and the owners of popular crates to hijack developer credentials and deploy malicious packages.

The crates.io team and the security response working group issued the warning. According to the alert, attackers lure targets into video calls under the guise of job offers or contract opportunities.

Once on the call, the target is tricked into installing software under the pretext of a missing audio codec or executing malicious code pasted to their clipboard.

To lend the approach credibility, the attackers are creating new companies with LinkedIn pages convincing enough to pass a quick look.

The Rust team connected the campaign to two earlier incidents. Many prominent Rust developers were targeted in a similar attack in June, and the arrayref crate was compromised for a short time in August through what the team described...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more