Find notable cyber news and cases, enriched with sources, timelines, and signals.

Rust crate-owner social engineering campaign via video calls

Campaign
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

The ongoing social engineering campaign against Rust-lang team members and popular crate owners threatens developer credentials and the integrity of crates.io packages. Attackers lure targets into video calls using fake job offers and contract opportunities, then push them to install software or execute clipboard-pasted code. The operation can lead to malicious packages being published from trusted accounts.

Related Happenings

Nimbus Manticore LinkedIn recruiter-persona cyber espionage campaign

Campaign
H score35 First: 01.09.2026 16:08 Last: 01.09.2026 16:08 Sources 1

About this happening: Nimbus Manticore has expanded a LinkedIn recruiter-persona campaign that uses trojanized coding challenge archives to deliver malware to technical targets. The operation i...

Arrayref maintainer account hit by network compromise

Incident
H score33 First: 20.08.2026 20:53 Last: 20.08.2026 20:53 Sources 1

About this happening: The arrayref maintainer account was compromised, and malicious crate releases on crates.io executed during compilation on developers’ systems, creating a supply-chain intr...

Latest development: 21.08.2026 15:40

Wiz researchers linked the Rust crates.io supply chain attack to state-sponsored North Korean threat actors, saying the arrayref infrastructure substantially overlaps with operations attributed to recent North Korean actors. Microsoft and other threat intelligence teams track the actor as Sapphire Sleet, and the network communication patterns, server setups, and endpoint paths mirrored prior supply-chain campaigns.

JINX-0164 cryptocurrency recruitment-lure campaign

Campaign
H score39 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...

AUDIOFIX and MiniRAT macOS malware activity

Malware Activity
H score34 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...

TrapDoor trap-core.js credential-stealing package malware

Malware Activity
H score34 First: 25.05.2026 08:59 Last: 25.05.2026 08:59 Sources 1

About this happening: The TrapDoor package malware is spreading across npm, PyPI, and Crates.io, putting developer secrets, cloud credentials, SSH keys, and crypto wallets at risk. The malw...

Timeline

  1. 21.09.2026 14:57 2 articles · 9h ago

    Rust warns of social engineering targeting crate owners via video calls

    Initial Disclosure

    The Rust project, crates.io team, and security response working group warned that an ongoing social engineering campaign is targeting Rust-lang team members and owners of popular crates to hijack developer credentials and deploy malicious packages. The attackers lure targets into video calls with fake job offers or contract opportunities, then try to get them to install software under the pretext of a missing audio codec or execute malicious code pasted to the clipboard; they are also creating fake companies with LinkedIn pages that can pass a quick look. The Rust team linked the activity to similar attacks in June and to the arrayref crate being compromised for a short time in August, but said it does not know whether the incidents are part of the same campaign.

    Show sources