www.securityweek.com 21 Sept 2026, 11:57 UTC

Rust Maintainers Targeted in Fake Recruiter Video Call Attacks

Rust Maintainers Targeted in Fake Recruiter Video Call Attacks
CyberSIXT Evidence Panel Source marked as original reporting

THE Rust project has warned of an ongoing social-engineering campaign targeting Rust team members and maintainers of popular crates. The crates.io team and security response working group said attackers are posing as recruiters or potential clients, inviting targets to video calls about job or contract opportunities. During calls, victims are persuaded to install software supposedly needed to fix a missing audio codec, or to execute malicious code copied to their clipboard. The attackers reportedly create convincing-looking companies and LinkedIn pages to make the approaches appear legitimate.

The Rust team linked the campaign to two earlier incidents, while noting it is not known whether all the activity has the same source. Prominent Rust developers were targeted in a similar attack in June, and the arrayref crate was briefly compromised in August after its developer’s account was taken over and malicious crates were published. That incident was linked to North Korean threat actors.

The latest alert said North Korea is known to use this style of attack, but did not attribute the current campaign to a specific actor. Developers have been advised to treat unsolicited approaches with caution, use trusted video-call platforms they control, review their accounts for suspicious activity, enable multi-factor authentication and check for unrecognised logins.

View full article

Article by CyberSIXT