A coordinated social engineering campaign is targeting prominent Rust developers and popular crates.io maintainers, using fake job or project video calls to trick them into installing malware or executing malicious commands. The attack has already succeeded in compromising packages such as array-ref, raising supply chain risks across the Rust ecosystem.
Background
Supply chain attacks on open source ecosystems have surged in recent years, with similar campaigns previously targeting RubyGems and other package registries. The Rust community is increasingly becoming a high-value target due to its growing popularity in systems programming.
- Source
- Simon Willison
- Published
- Sep 18, 2026 at 07:59 AM
- Score
- 6.0 / 10