The Rust project warned that attackers are using fake job offers and contract opportunities to lure Rust developers and crate owners into video calls, where they try to steal credentials and push malicious packages. The campaign has been linked to earlier incidents involving the arrayref crate and other Rust developers, with signs pointing to North Korean-style tradecraft. #Rust #cratesio #arrayref #NorthKorea
Keypoints
- Rust team members and popular crate owners are being targeted in a social engineering campaign.
- Attackers lure victims into video calls using fake job or contract offers.
- Victims are tricked into installing software or running malicious clipboard code.
- The attackers create fake companies and LinkedIn pages to appear legitimate.
- The campaign is connected to earlier incidents, including the arrayref compromise.
Read More: https://www.securityweek.com/rust-team-members-and-popular-crate-owners-targeted-via-video-calls/