Rust Warns That Its Developers and Crate Owners Are Being Targeted Through Fake Job Offers
The Rust security response working group and the Crates.io team have published a warning that a targeted campaign is underway against Rust language developers and owners of popular crates.
The objective is not the individuals. It is what they can publish.
How it works
From the security bulletin:
“A video call is set up for something positive, maybe for a job, maybe for a project, maybe for a contract opportunity, and then that’s used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard).
These attackers are setting up new but legitimate seeming company profiles, including plausible LinkedIn presences, in order to pass cursory inspection.”
Three things make this effective.
The pretext is welcome. A job offer, a contract, a collaboration. The target has a reason to want the conversation to be real, which is a considerably better starting position than a threatening email.
The infrastructure survives a check. A company website, a LinkedIn presence, plausible employees. Anyone who does the sensible thing and looks the company up finds something that looks fine.
The ask arrives mid-conversation. You are already on a call, already invested, and something technical does not work. A missing codec, a plugin, a setup command to paste. The request feels like friction rather than attack.
The clipboard variant deserves particular attention. Being asked to paste and run a command you did not write is the same shape as instructions that circulate as “fixes” for video call problems, and it works because the target performs the compromise themselves.
Why crate owners specifically
A maintainer account is a publishing key. Compromise one and you can push a malicious version of a package that thousands of projects pull automatically on their next build.
This is the supply-chain attack pattern that has repeatedly worked against npm and PyPI, applied to a registry whose packages increasingly sit in kernels, operating system components and security-critical userland. That relevance has grown sharply: Ubuntu now ships Rust coreutils by default, Google is replacing its C Binder driver with the Rust one, and Mold is rewriting itself in Rust with the goal of becoming the system linker.
The more important Rust becomes to the base system, the more valuable a crate publishing account is. Attacker attention is a lagging indicator of adoption.
What the project asks for
Multi-factor authentication on accounts, and general alertness to this pattern.
MFA is the specific control that matters here, because it turns a stolen password into an incomplete attack. Our SSH certificate authority guide and secrets management with SOPS and age cover the adjacent habits for anything you sign or publish.
Practical defence, for anyone who publishes anything
This campaign names Rust, and nothing about it is Rust-specific. If you maintain packages, containers, or an AUR entry, assume the pattern reaches you eventually.
- Treat an unexpected approach as unverified regardless of how good the company looks. A LinkedIn profile is not identity evidence
- Never run a command someone gives you during a call. There is no legitimate troubleshooting step that requires this from a stranger
- Be suspicious of your own clipboard. Paste into a text editor and read it before it reaches a shell
- Do development work in a VM or container when evaluating anything from a new contact, so a compromise has somewhere to stop. Our container hardening guide covers making that boundary real rather than nominal
- MFA on every publishing account, with hardware keys where the registry supports them
- Separate signing keys from your daily machine where practical
# what can your account publish
cargo owner --list <yourcrate>
# audit dependencies for known advisories
cargo install cargo-audit && cargo audit
The uncomfortable summary: the most effective attack on memory-safe code is not a memory-safety bug. It is asking the maintainer nicely.