Published September 17, 2026 ยท Added September 18, 2026

Be alert: targeted attacks on prominent Rustaceans

Adam Harvey, writing for the crates.io team and the Rust security response working group, warns that an ongoing campaign is targeting rust-lang members and owners of popular crates, using fake job, project, or contract video calls to trick maintainers into installing malware or running clipboard commands so their accounts can publish malicious releases, tactics previously used against the arrayref crate and attributed to the DPRK.

Adam Harvey, writing for the crates.io team and the Rust security response working group, warns that an ongoing campaign is targeting rust-lang members and owners of popular crates, using fake job, project, or contract video calls to trick maintainers into installing malware or running clipboard commands so their accounts can publish malicious releases, tactics previously used against the arrayref crate and attributed to the DPRK.

Read the original story.

Source: Rust Lang