Rust Team Members and Popular Crate Owners Targeted via Video Calls
The Rust project is warning developers about a sophisticated social engineering campaign targeting Rust team members and crate owners to steal credentials and deploy malicious packages. Attackers use convincing fake companies and lure victims into video calls under false pretenses, mirroring previous attacks linked to North Korean actors. Developers are urged to be extremely cautious and proactively secure their accounts.
The Rust project has issued a critical warning regarding an ongoing social engineering campaign targeting Rust-lang team members and the owners of popular crates. The campaign involves attackers leveraging video calls to trick developers into installing malicious software. These calls are presented as job offers or contract opportunities, and the attackers create new companies with LinkedIn pages to build credibility. The Rust team linked this campaign to two previous incidents, including a prior attack in June and the compromise of the arrayref crate in August. The arrayref incident, in particular, was linked to North Korean threat actors who compromised the account of arrayref’s developer and published several malicious crates. The Rust team is unsure if all these incidents are connected, but they emphasize the use of similar tactics. Developers are strongly advised to be vigilant against unsolicited approaches, to verify all video calls, and to thoroughly check their accounts for any unusual activity, including unrecognized logins. They should also ensure multi-factor authentication is enabled and confirm there are no unrecognized logins.