Mozilla Automation TeamAdam Harvey1 min readintro
Be alert: targeted attacks on prominent Rustaceans
Summary
The Mozilla Automation Team warns of a targeted social‑engineering campaign aimed at Rust community members and popular crate owners, using fake video‑call offers to deliver malware. They advise staying skeptical of cold outreach, using trusted call platforms, enabling MFA, and reporting any concerns to Rust security contacts.
- Attackers impersonate legitimate contacts via video calls to deliver malware or execute clipboard commands.
- Initiate calls on platforms you already trust and verify the caller's identity before installing anything.
- Enable MFA on all accounts and monitor for unexpected login activity.
- Report suspicious activity to help@crates.io or security@rust-lang.org.
Rust developers and crate maintainers should care because compromised accounts can be used to publish malicious crates that affect the entire ecosystem.
5/10
