Security News

Fake Job Interviews Target Rust Developers to Spread Malware

The Register · 21 Sept 2026
Key Takeaway Treat unsolicited job or contract offers involving video calls or software downloads with suspicion, and verify recruiters through trusted channels before installing anything or running commands they suggest.

The Rust project has issued a warning that its contributors and crate owners are being targeted by attackers using fake job interviews and recruitment approaches to compromise their devices and accounts. According to security engineer Adam Harvey, attackers set up convincing but fake company profiles, complete with plausible LinkedIn presences, and arrange video calls under the guise of job or contract opportunities. During these calls, victims are often tricked into installing malicious software, such as a fake audio codec, or running harmful commands.

This pattern echoes tactics seen in North Korean fake recruiter campaigns, which a recent advisory from agencies in Australia, Germany, Japan, and the US linked to the compromise of more than 30,000 devices and theft of over $10 million. Rust's ecosystem has already experienced related incidents this year, including a June attempt involving a fake Singaporean venture capital firm and an August supply chain attack where malicious versions of the popular arrayref crate were briefly published after a maintainer's credentials were likely compromised.

Harvey has urged Rust developers to be cautious of unsolicited recruitment approaches, even when they appear legitimate, and to conduct any related calls only through trusted, verified platforms.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.