Rust Developers Targeted in Ongoing Social Engineering Campaign
A sophisticated social engineering campaign is currently targeting members of the Rust project and owners of popular crates, with attackers attempting to hijack developer credentials and deploy malicious packages. The campaign, which has been ongoing for some time, involves attackers using video calls to trick targets into installing software or executing malicious code.
According to a warning issued by the Rust team, attackers are posing as job recruiters or contract offerers, luring victims into video calls under false pretenses. Once on the call, the attacker convinces the target to install software or execute code, often citing a missing audio codec or other technical issue as justification. To add credibility to their approach, attackers have been creating new companies with convincing LinkedIn profiles.
The Rust team has connected this campaign to two earlier incidents: a similar attack in June that targeted many prominent Rust developers and the compromise of the arrayref crate in August. While it is unclear whether all these incidents are part of the same campaign, the use of similar tactics suggests a coordinated effort. Notably, North Korea has been known to employ this style of attack, which has also been seen outside the Rust community.
Developers have been urged to exercise extreme caution when receiving unsolicited job offers or contract opportunities, and to hold video calls with new contacts on trusted platforms that they set up themselves. They should also regularly review their accounts for any unusual activity, ensure multi-factor authentication is enabled, and confirm there are no unrecognized logins. By being vigilant and taking these precautions, developers can significantly reduce the risk of falling victim to this type of attack.
The Rust project’s warning serves as a timely reminder that social engineering attacks remain a significant threat in the cybersecurity landscape. As attackers continue to evolve their tactics, it is essential for developers and organizations to stay informed and take proactive steps to protect themselves against these types of threats.
Source: SecurityWeek — 2026-09-21