PunchFunke Akindele sparks online debate after missing Kamo’s movie premiereBollywood HungamaHanuman Ansh team meets Home Minister Amit Shah in New DelhiESPNTransfer rumors, news: Arsenal eye versatile Dortmund forwardDaily MaverickKremlin says AfD’s victory in Germany due in large part to lack of cheap Russian gasRTP DesportoFederação suíça castiga capitão Xhaka por falsificação de certificado covid-19ESPN DeportesIsaac del Toro conquista a rivales y aficionados en el MundialInquirerSurigao del Norte forest fire threatens Philippine eagle nests20 Minuten«Xhaka ist ein Spieler mit Charisma» – Knäbel nach der Impf-LügeVilaWeb[EN DIRECTE] Compareix al congrés espanyol Emilio Argüeso, el cap d’Emergències absent durant la gota fredaRTL BoulevardEngeland ziet vijf spelers afhaken voor komende interlandperiodeThe South AfricanFerrari Amalfi and Purosangue tamed on SA roadsStraits Times SportBeing managed by Zidane for France is 'like a movie', says Mbappe
The Daily Newsstand · Free, Always
Monday, September 21, 2026

Rustaceans warned of job interviews with a malicious payload

Translate

Attackers are courting crate owners with plausible company profiles and booby-trapped recruitment calls

The Rust project has warned that attackers appear to be targeting its contributors and crate owners in an attempt to compromise their devices and accounts, potentially allowing malware to be distributed through its package ecosystem.

Posting to the Rust blog, security-focused software engineer Adam Harvey said the tactics resemble those used in North Korean fake recruiter campaigns.

"A video call is set up for something positive – maybe for a job, maybe for a project, maybe for a contract opportunity – and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard)," Harvey wrote.

REG AD

"These attackers are setting up new but legitimate-seeming company profiles, including plausible LinkedIn presences, in order to pass cursory inspection."

REG AD

The warning follows several attacks targeting the Rust community over the summer.

In June, Rust developers were targeted with fake interview approaches purporting to come from a Singaporean venture capital firm. Matt Mastracci, who maintains packages on Rust's crates.io registry, said the supposedly recruiting business turned out to be defunct. The initial approach nevertheless appeared convincing and almost led to his machine being infected with a remote access trojan (RAT).

The attempted deployment of a RAT resembles activity described in an international advisory issued last week by agencies in Australia, Germany, Japan, and the US. The advisory said North Korean operators had used fake job interviews to compromise more than 30,000 devices and steal over $10 million.

Separately, Rust's package ecosystem suffered a supply chain attack in August, when malicious versions of the arrayref crate were published that downloaded malware onto users' machines.

Arrayref had recorded 245 million downloads over its lifetime, although the malicious releases were available for less than two hours. The evidence suggested that a maintainer's credentials had been compromised rather than the malware being deliberately introduced by the project's developers.

Harvey urged Rustaceans to scrutinize unsolicited approaches even when the sender appears legitimate, and to conduct calls through trusted platforms. ®

View the original on The Register

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.