‼️ Rust’s best-known maintainers are under attack. Attackers lure victims into installing malware by pretending to have good news.
They start with a friendly video call about a job, contract, or project. Then they ask the victim to install a missing audio codec or run a command from the clipboard.
The goal is the publishing account, so malware can ship under a trusted name.
This has worked before. Prominent Rust developers were hit the same way in June, and last month the arrayref crate was briefly compromised.
The Rust team does not yet know if this is one campaign. The technique is known from North Korean operations, but they are not attributing this one.
https://blog.rust-lang.org/2026/09/17/targeted-attacks/
Post #1598
1.43K


- 🤬 10
- 😱 5
- 🔥 3
- 🤣 2