Targeted attacks on prominent Rust developers use fake video calls to deploy malware
Simon Willison · rss · 2026-09-18
Adam Harvey and the crates security team warn of an ongoing campaign targeting rust-lang members and popular crate owners, aiming to compromise their devices and accounts to publish malware.
- Attackers lure targets into video calls framed as job or contract opportunities, then push them to install a "missing audio codec" or execute a command via the clipboard.
- Last month this trick enabled a successful supply chain attack on the arrayref crate, among others.
More from Safety
- Security experts clash: two frontier models can now autonomously execute the full cyber kill chain — AccBalanced · 2026-09-18
- Stanford philosopher defends p(doom): subjective probabilities are perfectly legitimate — sethlazar · 2026-09-18
- Hugging Face hit by AI-led cyberattack; CEO says existing cyber laws may suffice — whurley · 2026-09-18
- Steve Eisman: AI firms have no moats and are manufacturing a crisis to shape regulation — GaryMarcus · 2026-09-18
- AI text watermarking can make models more vulnerable to adversarial prompts — luisdans · 2026-09-18
- Can AI exfiltrate data via fan noise from air-gapped PCs? Casado and Jensen clash — basedjensen · 2026-09-18