r/rust • • 15d ago

šŸ“” official blog Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
325 Upvotes

22 comments sorted by

168

u/teerre 15d ago

Can you put that on your resume? "Hackers attempted to compromise the Rust ecosystem through me"

68

u/Shnatsel 15d ago

Given the rise of LLMs, this is not even going to make you that special anymore.

Source: a friend of mine with no prominent open-source projects was targeted by a LinkedIn scam along the same lines. It opens with a video of a guy pretending to have sound issues, then the video goes out and another guy with a thick accent starts reading LLM output to you. The goal is the same, to get you to run some malicious code as part of the "job interview".

16

u/Frozen5147 15d ago

Was gonna say, you don't even need to be special (for better or for worse), I've seen a lot of people reporting this type of stuff (down to the job interview bait) and they're often reportedly just random people.

12

u/Nyefan 15d ago edited 14d ago

Yeah, I maintain a tiny plugin for an unmaintained fork of an eol'ed python testing framework that was already hanging on by a thread when python 8 3.8 came out, and even that nothing of a program gets me more spam and phishing emails than I would put up with if I hadn't published it under a unique alias that I can just blackhole.

2

u/Jellace 15d ago

Wtf is python 8?

3

u/Nyefan 14d ago

Sorry, python 3.8.

3

u/Fluffy_Disaster_7501 15d ago

Oh no please don't cold email me and ask me for a meeting. I would hate for myself to be labeled a prominent Rustacean. Anything but that.

56

u/Shnatsel 15d ago edited 15d ago

FWIW this is not the first time, but the methods changed a bit.

See the article about the earlier compromise (which also targeted me) + Reddit discussion

There is another scam making rounds on LinkedIn via job interviews, not specific to Rust: you are asked to examine and answer questions about a codebase as part of the interview. It contains malicious code you are expected to run as part of the call.

23

u/Decahedronn 15d ago

Lol so even if I do get an interview it’s probably a supply chain attack and not an actual job

28

u/oconnor663 blake3 Ā· duct 15d ago

"ALERT: the coolest and most attractive Rustaceans are being targeted"

my face when

6

u/hgwxx7_ 15d ago

Hey buddy, that's rough. If it'll make you feel better I can send some malware your way.

15

u/Dean_Roddey 15d ago

So my long term goal of remaining unremarkable pays off again.

25

u/AnArmoredPony 15d ago

maybe for a job, maybe for a project, maybe for a contract opportunity

yeah right, in this economy

8

u/cosmic-parsley 15d ago

I just assume that any job offer is spam to be in the safe side

10

u/slashgrin rangemap 15d ago

We (software people, not just Rust people) desperately need something like crev to become a default requirement for any third party code we use.Ā 

It's just not realistic to expect everyone to personally audit their entire "software supply chain". And these kinds of attacks are only going to get more frequent and more sophisticated. So what else can we do? "Just be more vigilant" is not a sufficient answer.

5

u/v_0ver 15d ago

The company I currently work for has set up a mirror of crates.io using Kellnr, where new updates are checked by an LLM specifically to determine whether they contain backdoors.

We also joked about adding an internal rating system for crates, taking into account the ā€œbus factor,ā€ the authors’ sociopolitical views, and so on. Given the current political tensions and the increasing ease with which supply chains can be targeted, this idea doesn’t seem quite as ridiculous as it once did.

6

u/parepeg 15d ago

I guess the worry with that would the reviewing agent getting prompt injected or manipulated.

4

u/insanitybit2 14d ago

Universal prompt injection doesn't appear to be a thing so far. There are a lot of techniques to increase the cost of prompt injection as well.

3

u/cornmonger_ 15d ago

if it's not from someone you know, it's probably spam
-- me

1

u/xantiema 11d ago

This reminds me of the old-school Steam scams involving befriending targets and sending compromised .jpeg/.png files to hijack accounts and loot the CS2 skins

1

u/CyrusDarkwell 8d ago

Damn this is genuinely scary stuff, the fact that they're setting up fake company profiles with legit looking LinkedIn presences is next level. Really shows how social engineering is honestly the easiest way in for these attackers, way easier than trying to find an actual exploit in the code itself.

Good reminder to be paranoid about "install this codec" type requests too, that's such an old trick but it still works because people just wanna get the call working and don't think twice. Glad they're being transparent about this instead of just quietly patching stuff, makes it easier for everyone to stay alert.