conv.

All stories
SecurityQuiet 3d · day 7

Rust project warns of coordinated attacks on prominent developers

The Rust Foundation alerts crate owners and team members to a campaign using fake job offers and impersonated companies to compromise accounts.

What to know

  • Rust developers and crate maintainers are being targeted by a coordinated social engineering campaign using fake job offers and impersonated companies to compromise accounts and publish malware.
  • Attackers use video calls to trick targets into installing malicious payloads disguised as missing codecs or clipboard commands, leveraging fake LinkedIn profiles to establish credibility.
  • The Rust team recommends enabling MFA, verifying account activity, being suspicious of cold outreach, and initiating any calls with new contacts on trusted platforms.

“A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command.”

Rust project, Security issuer · Rust Blog · Sep 16

Rust project / Rust Foundation Security issuer

Rust project warns of coordinated attacks on prominent developers
blog.rust-lang.org

How it unfolded 1 development · click the chart to see its coverage posts

Peak 5 pieces in two hours at Sep 17, 1 PM; 51 pieces over 7 days (1 article · 9 posts · 41 comments) Sep 17, 1 PM — 5 pieces · 4 posts · 1 comment — Lobsters 2, Hacker News 1, Mastodon 1, +1 moreSep 17, 3 PM — 1 piece · 1 post — Mastodon 1Sep 17, 5 PM — 1 piece · 1 post — Mastodon 1Sep 17, 7 PM — 3 pieces · 1 article · 2 comments — Lobsters 1, Reddit 1, Newswires 1Sep 17, 9 PM — 2 pieces · 1 post · 1 comment — Hacker News 1, Reddit 1Sep 17, 11 PM — quietSep 18, 1 AM — 1 piece · 1 comment — Lobsters 1Sep 18, 3 AM — 2 pieces · 2 comments — Lobsters 2Sep 18, 5 AM — 2 pieces · 2 comments — Lobsters 2Sep 18, 7 AM — 4 pieces · 4 comments — Lobsters 4Sep 18, 9 AM — 5 pieces · 1 post · 4 comments — Lobsters 4, Mastodon 1Sep 18, 11 AM — 5 pieces · 5 comments — Lobsters 5Sep 18, 1 PM — 3 pieces · 3 comments — Lobsters 2, Reddit 1Sep 18, 3 PM — 1 piece · 1 comment — Lobsters 1Sep 18, 5 PM — 1 piece · 1 comment — Lobsters 1Sep 18, 7 PM — 2 pieces · 2 comments — Lobsters 2Sep 18, 9 PM — 1 piece · 1 comment — Lobsters 1Sep 18, 11 PM — quietSep 19, 1 AM — 1 piece · 1 comment — Reddit 1Sep 19, 3 AM — 2 pieces · 2 comments — Lobsters 2Sep 19, 5 AM — 2 pieces · 2 comments — Lobsters 2Sep 19, 7 AM — 1 piece · 1 comment — Lobsters 1Sep 19, 9 AM — 2 pieces · 2 comments — Lobsters 2Sep 19, 11 AM — 2 pieces · 2 comments — Lobsters 2Sep 19, 1 PM — quietSep 19, 3 PM — quietSep 19, 5 PM — quietSep 19, 7 PM — quietSep 19, 9 PM — quietSep 19, 11 PM — quietSep 20, 1 AM — quietSep 20, 3 AM — 1 piece · 1 post — Mastodon 1Sep 20, 5 AM — quietSep 20, 7 AM — quietSep 20, 9 AM — quietSep 20, 11 AM — quietSep 20, 1 PM — quietSep 20, 3 PM — quietSep 20, 5 PM — quietSep 20, 7 PM — quietSep 20, 9 PM — quietSep 20, 11 PM — quietSep 21, 1 AM — 1 piece · 1 comment — Lobsters 1Sep 21, 3 AM — quietSep 21, 5 AM — quietSep 21, 7 AM — quietSep 21, 9 AM — quietSep 21, 11 AM — quietSep 21, 1 PM — quietSep 21, 3 PM — quietSep 21, 5 PM — quietSep 21, 7 PM — quietSep 21, 9 PM — quietSep 21, 11 PM — quietSep 22, 1 AM — quietSep 22, 3 AM — quietSep 22, 5 AM — quietSep 22, 7 AM — quietSep 22, 9 AM — quietSep 22, 11 AM — quietSep 22, 1 PM — quietSep 22, 3 PM — quietSep 22, 5 PM — quietSep 22, 7 PM — quietSep 22, 9 PM — quietSep 22, 11 PM — quietYesterday, 1 AM — quietYesterday, 3 AM — quietYesterday, 5 AM — quietYesterday, 7 AM — quietYesterday, 9 AM — quietYesterday, 11 AM — quietYesterday, 1 PM — quietYesterday, 3 PM — quietYesterday, 5 PM — quietYesterday, 7 PM — quietYesterday, 9 PM — quietYesterday, 11 PM — quietToday, 1 AM — quietToday, 3 AM — quietToday, 5 AM — quietToday, 7 AM — quietToday, 9 AM — quietToday, 11 AM — quietToday, 1 PM — quiet 1
Sep 18Sep 19Sep 20Sep 21Sep 22yesterdaynow · 2:28 PM ET
  1. 1

    Rust team issues mitigation guidance and support contacts

    The project advised developers to enable MFA, verify account logins, be suspicious of unsolicited contacts, and to reach out to help@crates.io or security@rust-lang.org if they had account concerns.

    “Be appropriately suspicious of cold outreaches, and ensure that any calls you have with new people are on platforms you trust — ideally, try to be the one who sets up the call on a platform you already use.”
    — Rust project
    • rust@social.rust-lang.org

      ⚠️ We believe that there is an ongoing campaign targeting owners of popular crates and rust-lang team members that is attempting to compromise devices and accounts in order to use them to publish malware. See our blog post for details: https:// blog.rust-lang.org/2026/09/17/ targeted-attacks/

      rust@social.rust-lang.orgMastodon6d ago247▲view on Mastodon ↗
    2 more of the top 3 · 43 posts in this stretch
    • recently, systemd-the-organisation looked at introducing rust as a part of systemd-the-init. luca boccassi, one of the senior maintainers[1] of systemd-the-both, [raised some good points about it](https://github.com/systemd/systemd/pull/43551#issuecomment-5445121831). i've stripped what i'll describe as somewhat _extreme_ exaggerations around…

      arcayrrust,security6d ago31▲view on Lobsters ↗
    • It's not a bad design choice just because it has consequences. Rust also doesn't have the financial backing of languages that seem to be able to afford a kitchen sink in their std lib. Python also suffers from stdlib rot from people not maintaining parts of it, and C++ can't fix their stdlib speed deficiencies because of ABI issues and backward…

      Plazmaticr/programming6d agoview on r/programming ↗
    all of them →
  2. background

    Attackers use fake company profiles to appear legitimate — The advisory detailed that attackers create new company profiles with plausible LinkedIn presences designed to pass initial scrutiny, allowing them to initiate seemingly professional contact with Rust developers.

  3. background

    Rust project discloses coordinated malware campaign targeting developers — The Rust project published a security advisory warning of an ongoing campaign targeting rust-lang members and owners of popular crates. The attackers set up video calls under pretenses of job offers, projects, or contracts, then use those calls to socially engineer targets into installing malware or executing commands via fake audio codecs or clipboard manipulation.

What people are saying 21 voices from 3 sites · best of 43 · verbatim