Rust Developers Targeted in Social Engineering Campaign Using Fake Job Offers
The Rust project is warning developers about a social engineering campaign using fake job offers and video calls to trick targets into installing malware or executing malicious code.

The Rust project has issued a stern warning regarding an ongoing social engineering campaign that is actively targeting members of the Rust-lang team and owners of popular Rust crates. The primary objective of this malicious operation appears to be the hijacking of developer credentials and the subsequent deployment of malicious packages within the software supply chain.
The crates.io team and the Rust security response working group detailed the modus operandi in a recent alert. Attackers are reportedly luring unsuspecting targets into video calls by presenting themselves with convincing fake job offers or contract opportunities. These fabricated opportunities are often backed by newly created companies with seemingly legitimate LinkedIn pages, designed to pass initial scrutiny and build trust with potential victims.
During these video calls, the attackers employ deceptive tactics to persuade the target into installing unauthorized software or executing malicious code. Common pretexts include claiming a need for a missing audio codec to facilitate the call, or instructing the victim to paste code into their system, which is, in fact, malicious.
This campaign bears a striking resemblance to at least two prior incidents. In June, a significant number of prominent Rust developers were subjected to similar attack vectors. Furthermore, in August, the arrayref crate experienced a brief compromise attributed to attacks with a similar methodology. While the Rust team has not definitively confirmed if all these events are part of a single, unified campaign, the pattern of targeting is highly suggestive.
SecurityWeek has previously reported on the arrayref incident, which was initially linked to North Korean threat actors. In that instance, attackers successfully compromised the account of the arrayref crate's developer, leading to the publication of several malicious versions of the crate. The current campaign's tactics align with known methods employed by North Korean state-sponsored groups, although the Rust team has not officially attributed the current activity to any specific actor.
In light of these threats, developers are strongly advised to exercise extreme caution when receiving unsolicited approaches. It is recommended to conduct calls with new contacts on platforms that are personally trusted and preferably self-managed. Additionally, developers should regularly review their accounts for any suspicious activity, ensure that multi-factor authentication is enabled across all services, and verify that no unrecognized logins are present.
The sophistication of these attacks underscores the persistent threat to the software development ecosystem. By targeting key individuals and trusted repositories, threat actors aim to infiltrate the supply chain, potentially impacting a wide range of downstream users. The use of social engineering, coupled with the creation of seemingly legitimate front companies, highlights the evolving tactics employed by malicious actors seeking to compromise software integrity.
This new report from The Register details how attackers are specifically targeting Rust contributors and crate owners, employing social engineering tactics during fake job interviews to trick victims into installing malware or executing malicious commands. The campaign, which includes setting up fake company profiles and LinkedIn presences, bears a strong resemblance to North Korean fake recruiter campaigns that have led to global compromises.