Back blog.rust-lang.org blog post about the malicious campaign.
We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware.
A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard).
These attackers are setting up new but legitimate seeming company profiles, including plausible presences, in order to pass cursory inspection.
A attack of this form targeted many prominent Rust developers in June, and, last month, the arrayref crate was briefly compromised through similar attacks . At this moment we do not know if these are all a part of the same campaign.
This attack style is known to be used by the DPRK , and has been seen outside of the Rust community as well .
Please take extra care in the near term. Be appropriately suspicious of cold outreaches, and ensure that any calls you have with new people are on platforms you trust — ideally, try to be the one who sets up the call on a platform you already use.
Please also re-check that your accounts look normal: MFA enabled, no unexpected logins on platforms that can track that, and so on.
If you have any concerns your accounts, please reach out to [email protected] (for crates.io account concerns) and/or [email protected] (for any other concerns). We're very happy to help.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
