Rust crate-owner social engineering campaign via video calls
Campaign
Summary
Hide ▲
Show ▼
The ongoing social engineering campaign against Rust-lang team members and popular crate owners threatens developer credentials and the integrity of crates.io packages. Attackers lure targets into video calls using fake job offers and contract opportunities, then push them to install software or execute clipboard-pasted code. The operation can lead to malicious packages being published from trusted accounts.
Related Happenings
Nimbus Manticore LinkedIn recruiter-persona cyber espionage campaign
Campaign
H score35
First: 01.09.2026 16:08
Last: 01.09.2026 16:08
Sources 1
About this happening:
Nimbus Manticore has expanded a LinkedIn recruiter-persona campaign that uses trojanized coding challenge archives to deliver malware to technical targets. The operation i...
Nimbus Manticore LinkedIn recruiter-persona cyber espionage campaign
CampaignAbout this happening: Nimbus Manticore has expanded a LinkedIn recruiter-persona campaign that uses trojanized coding challenge archives to deliver malware to technical targets. The operation i...
Arrayref maintainer account hit by network compromise
Incident
H score33
First: 20.08.2026 20:53
Last: 20.08.2026 20:53
Sources 1
About this happening:
The arrayref maintainer account was compromised, and malicious crate releases on crates.io executed during compilation on developers’ systems, creating a supply-chain intr...
Arrayref maintainer account hit by network compromise
IncidentAbout this happening: The arrayref maintainer account was compromised, and malicious crate releases on crates.io executed during compilation on developers’ systems, creating a supply-chain intr...
Latest development: 21.08.2026 15:40
Wiz researchers linked the Rust crates.io supply chain attack to state-sponsored North Korean threat actors, saying the arrayref infrastructure substantially overlaps with operations attributed to recent North Korean actors. Microsoft and other threat intelligence teams track the actor as Sapphire Sleet, and the network communication patterns, server setups, and endpoint paths mirrored prior supply-chain campaigns.
JINX-0164 cryptocurrency recruitment-lure campaign
Campaign
H score39
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
JINX-0164 cryptocurrency recruitment-lure campaign
CampaignAbout this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
AUDIOFIX and MiniRAT macOS malware activity
Malware Activity
H score34
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...
AUDIOFIX and MiniRAT macOS malware activity
Malware ActivityAbout this happening: The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...
TrapDoor trap-core.js credential-stealing package malware
Malware Activity
H score34
First: 25.05.2026 08:59
Last: 25.05.2026 08:59
Sources 1
About this happening:
The TrapDoor package malware is spreading across npm, PyPI, and Crates.io, putting developer secrets, cloud credentials, SSH keys, and crypto wallets at risk. The malw...
TrapDoor trap-core.js credential-stealing package malware
Malware ActivityAbout this happening: The TrapDoor package malware is spreading across npm, PyPI, and Crates.io, putting developer secrets, cloud credentials, SSH keys, and crypto wallets at risk. The malw...
Timeline
-
21.09.2026 14:57 2 articles · 9h ago
Rust warns of social engineering targeting crate owners via video calls
Initial DisclosureThe Rust project, crates.io team, and security response working group warned that an ongoing social engineering campaign is targeting Rust-lang team members and owners of popular crates to hijack developer credentials and deploy malicious packages. The attackers lure targets into video calls with fake job offers or contract opportunities, then try to get them to install software under the pretext of a missing audio codec or execute malicious code pasted to the clipboard; they are also creating fake companies with LinkedIn pages that can pass a quick look. The Rust team linked the activity to similar attacks in June and to the arrayref crate being compromised for a short time in August, but said it does not know whether the incidents are part of the same campaign.
Show sources
- Rust Team Members and Popular Crate Owners Targeted via Video Calls — www.securityweek.com — 21.09.2026 14:57
- Rust Team Members and Popular Crate Owners Targeted via Video Calls — www.securityweek.com — 21.09.2026 14:57