Rust Project maintainers and crate developers are being targeted by attackers who pose as recruiters or collaborators to trick victims into running malicious code or revealing credentials. The campaign is linked to Contagious Interview (aka WaterPlum), a North Korean operation that has compromised thousands of devices and cryptocurrency wallets worldwide. #RustProject #ContagiousInterview #WaterPlum #cratesio
Keypoints
- Attackers lure Rust developers through fake job and collaboration offers.
- Victims are pressured to run malicious commands or install software during interviews.
- Contagious Interview also targets software developers, IT workers, and job seekers.
- The group has stolen credentials, crypto funds, and sensitive data across many countries.
- Defenses include verifying contacts, using sandboxes, enabling MFA, and screening for fake remote workers.
Read More: https://www.helpnetsecurity.com/2026/09/21/north-korean-hackers-contagious-interview-defenses/