Skip to content
Rust Team Members and Popular Crate Owners Targeted via Video Calls

Rust Team Members and Popular Crate Owners Targeted via Video Calls

Securityweek • September 21, 2026

The Rust project warned last week that an ongoing social engineering campaign is targeting Rust-lang team members and the owners of popular crates to hijack developer credentials and deploy malicious packages.

The crates.io team and the security response working group issued the warning. According to the alert, attackers lure targets into video calls under the guise of job offers or contract opportunities.

Once on the call, the target is tricked into installing software under the pretext of a missing audio codec or executing malicious code pasted to their clipboard.

To lend the approach credibility, the attackers are creating new companies with pages convincing enough to pass a quick look.

The Rust team connected the campaign to two earlier incidents. Many prominent Rust developers were targeted in a similar attack in June , and the arrayref crate was compromised for a short time in August through what the team described as similar attacks. It said it does not know whether all of these incidents are part of the same campaign.

SecurityWeek previously reported on the arrayref incident , which surfaced on August 20 and was linked to North Korean threat actors. The attackers had compromised the account of arrayref’s developer and published several malicious crates.

In the new alert, the Rust team noted that North Korea is known to use this style of attack, which has also been seen outside the Rust community. It did not name a specific actor behind the current activity.

Developers have been urged to be wary of unsolicited approaches and to hold calls with new contacts on platforms they trust, preferably one they set up themselves. They should also check their accounts for anything unusual, ensure multi-factor authentication is enabled, and confirm there are no unrecognized logins.

Related : Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages

Related : Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

Related : Multiple Jscrambler Packages Impacted by Supply Chain Attack

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

More from Eduard Kovacs

23 Million User Records Compromised in Gyazo Data Breach

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

Pixel Modem Zero-Day Exploited in Targeted Attacks

RatHat Android Trojan Uses AI for Automation

CrowdSec Confirms Source Code Stolen in Supply Chain Attack

Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities

Google Confirms Gemini AI Breached Three Firms

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

Virtual Event: Attack Surface Management Summit 2026

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Webinar: Building Continuous Authorization at Scale

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Flipboard Whatsapp Whatsapp Email

Extracted Entities

Countries (1)

Platforms (2)