The Rust security response working group and Crates.io team have issued a warning that a targeted attack is underway against key Rust programming language developers. Key members of the Rust-Lang team for developing the Rust programming language as well as owners of popular Rust crates are reportedly being targeted to compromise their devices and accounts in order to distribute malware in the Rust ecosystem. The attack(s) appear to be sophisticated with setting up fake LinkedIn profiles and then targeting developers to install malicious software as part of job recruiting or contracting opportunities: "A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard). These attackers are setting up new but legitimate seeming company profiles, including plausible LinkedIn presences, in order to pass cursory inspection." In today's security bulletin they are encouraging Rust developers to be on alert and ensure their accounts are using multi-factor authentication and other security safeguards.
Rust Issues Warning Over Key Developers Being Targeted For Compromise
Full Article
Original Source
Read the full article at Phoronix →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.