Adam Harvey, writing for the crates.io team and the Rust security response working group, warns that an ongoing campaign is targeting rust-lang members and owners of popular crates, using fake job, project, or contract video calls to trick maintainers into installing malware or running clipboard commands so their accounts can publish malicious releases, tactics previously used against the arrayref crate and attributed to the DPRK.
Be alert: targeted attacks on prominent Rustaceans
Adam Harvey, writing for the crates.io team and the Rust security response working group, warns that an ongoing campaign is targeting rust-lang members and owners of popular crates, using fake job, project, or contract video calls to trick maintainers into installing malware or running clipboard commands so their accounts can publish malicious releases, tactics previously used against the arrayref crate and attributed to the DPRK.
Source: Rust Lang