The Rust project is warning that attackers are targeting team members and maintainers of popular crates with fake job and contract opportunities designed to steal credentials and compromise software packages.
The campaign begins with an unsolicited approach from a plausible recruiter or newly created company. Attackers build credible-looking LinkedIn profiles, invite the target to a video call, then manufacture a technical problem that supposedly requires a codec installation or a command pasted from the clipboard.
A supply-chain target, not just an individual
Compromising a crate maintainer can give an attacker the ability to publish malicious versions of a widely used dependency. Rust developers faced a similar wave in June, and the arrayref crate was briefly compromised in August after an attacker took over its developer’s account and published malicious packages.
The Rust team has not attributed the current activity to a specific group or confirmed that the incidents are all connected. However, North Korean operators have repeatedly used fake recruitment and coding-interview lures against developers, cryptocurrency staff and technology companies.
A separate international advisory on the campaign known as Contagious Interview said related activity infected more than 30,000 devices across over 100 countries between December 2025 and July 2026 and stole funds or credentials associated with more than 7,000 cryptocurrency wallets.
How developers can reduce the risk
- Independently verify recruiters and companies instead of trusting profile history or shared connections.
- Create the meeting invitation yourself and use a platform you already trust.
- Do not install codecs, extensions or meeting software at the request of a new contact.
- Run take-home assignments and unfamiliar repositories only inside disposable virtual machines.
- Open unknown Visual Studio Code projects in Restricted Mode.
- Enable phishing-resistant multi-factor authentication on package registries and review recent logins.
What organizations should monitor
Security teams should treat developer workstations as privileged infrastructure. These systems often hold package-publishing tokens, cloud credentials, SSH keys and access to build pipelines. Controls should include endpoint detection, short-lived credentials, hardware-backed authentication, protected publishing workflows and alerts for new package releases or token creation.
Hiring teams should also watch for the other side of the threat: operatives using stolen identities to obtain remote employment and access to corporate systems.
Sources
- SecurityWeek: Rust Team Members and Popular Crate Owners Targeted via Video Calls
- Rust Project: Targeted attacks against Rust maintainers
- Help Net Security: North Korea’s job interview scam runs both ways
