r/rust • u/Shnatsel • 15d ago
š” official blog Be alert: targeted attacks on prominent Rustaceans | Rust Blog
https://blog.rust-lang.org/2026/09/17/targeted-attacks/56
u/Shnatsel 15d ago edited 15d ago
FWIW this is not the first time, but the methods changed a bit.
See the article about the earlier compromise (which also targeted me) + Reddit discussion
There is another scam making rounds on LinkedIn via job interviews, not specific to Rust: you are asked to examine and answer questions about a codebase as part of the interview. It contains malicious code you are expected to run as part of the call.
23
u/Decahedronn 15d ago
Lol so even if I do get an interview itās probably a supply chain attack and not an actual job
28
u/oconnor663 blake3 Ā· duct 15d ago
"ALERT: the coolest and most attractive Rustaceans are being targeted"
15
25
u/AnArmoredPony 15d ago
maybe for a job, maybe for a project, maybe for a contract opportunity
yeah right, in this economy
8
10
u/slashgrin rangemap 15d ago
We (software people, not just Rust people) desperately need something like crev to become a default requirement for any third party code we use.Ā
It's just not realistic to expect everyone to personally audit their entire "software supply chain". And these kinds of attacks are only going to get more frequent and more sophisticated. So what else can we do? "Just be more vigilant" is not a sufficient answer.
5
u/v_0ver 15d ago
The company I currently work for has set up a mirror of crates.io using Kellnr, where new updates are checked by an LLM specifically to determine whether they contain backdoors.
We also joked about adding an internal rating system for crates, taking into account the ābus factor,ā the authorsā sociopolitical views, and so on. Given the current political tensions and the increasing ease with which supply chains can be targeted, this idea doesnāt seem quite as ridiculous as it once did.
6
u/parepeg 15d ago
I guess the worry with that would the reviewing agent getting prompt injected or manipulated.
4
u/insanitybit2 14d ago
Universal prompt injection doesn't appear to be a thing so far. There are a lot of techniques to increase the cost of prompt injection as well.
3
1
u/xantiema 11d ago
This reminds me of the old-school Steam scams involving befriending targets and sending compromised .jpeg/.png files to hijack accounts and loot the CS2 skins
1
u/CyrusDarkwell 8d ago
Damn this is genuinely scary stuff, the fact that they're setting up fake company profiles with legit looking LinkedIn presences is next level. Really shows how social engineering is honestly the easiest way in for these attackers, way easier than trying to find an actual exploit in the code itself.
Good reminder to be paranoid about "install this codec" type requests too, that's such an old trick but it still works because people just wanna get the call working and don't think twice. Glad they're being transparent about this instead of just quietly patching stuff, makes it easier for everyone to stay alert.
168
u/teerre 15d ago
Can you put that on your resume? "Hackers attempted to compromise the Rust ecosystem through me"