Rust developers targeted by hackers with fake job calls and malicious commands
A job offer that developers should definitely refuse.

Rust Foundation. Image by Cybernews
- Attackers pose as recruiters or project leads to lure Rust developers into one-to-one video calls.
- During calls, they ask targets to install files or run commands that may compromise devices and accounts.
- Scammers use legitimate-looking company profiles, including LinkedIn accounts, to make the outreach appear trustworthy.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Hackers have set their sights on Rust developers, aiming to compromise their devices and distribute malware.
According to Adam Harvey, a software engineer at the Rust Foundation, the campaign starts with a one-to-one video call, such as for a job interview, a contract opportunity, or project participation.
During the call, the attacker wants the target to install a file on their system – often something like a supposedly missing audio codec – or execute a command.
The goal is to take control of the target’s devices and accounts to distribute malware.
To avoid suspicion, the scammers have set up new but legitimate-looking company profiles, including a LinkedIn account.
“Please take extra care in the near term. Be appropriately suspicious of cold outreaches, and ensure that any calls you have with new people are on platforms you trust – ideally, try to be the one who sets up the call on a platform you already use,” Harvey recommends in a blog post about the malicious campaign.
In addition, Rust developers should double-check that their accounts appear normal and monitor for unexpected logins. Ideally, to better protect their accounts, developers should enable multi-factor authentication (MFA).
Unfortunately, the Rust Foundation, an independent nonprofit organization that supports the Rust programming language, doesn’t provide many details about the active malware campaign.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
It remains unclear how widespread the attacks are, what the malware does once it has been installed, or who’s responsible for the campaign.
The foundation says that many prominent Rust developers were attacked in June. Last month, the arrayref crate was briefly compromised through similar attacks. “At this moment, we do not know if these are all a part of the same campaign,” Harvey concludes.
Campaigns in which victims are approached by fake recruiters with unique “dream job” offers have been used by state-linked hackers from the Democratic People’s Republic of Korea (DPRK), the official name of North Korea.