Be alert: targeted attacks on prominent Rustaceans
3 hours ago
- An ongoing campaign is targeting rust-lang members and popular crate owners to compromise devices and accounts for malware distribution.
- Attackers use video calls under positive pretexts (e.g., job interviews) and trick victims into installing malicious software or executing commands.
- They create seemingly legitimate company profiles and LinkedIn presences to evade scrutiny.
- Recommendations include being suspicious of cold outreach, using trusted platforms for calls, and checking account security (e.g., MFA, login history).
- Victims should report concerns to help@crates.io or security@rust-lang.org.