Fake Rust Job Interviews Push Malware on Devs

The Register Security · High sophistication
Last updated September 21, 2026

The Rust Project warned that attackers are approaching Rust contributors and crate maintainers with believable recruiter outreach and “company” profiles, then using interview video calls to trick targets into installing malware or running commands. The activity is described as similar to North Korean fake-recruiter campaigns and could lead to account takeover and malicious code being distributed through the Rust package ecosystem.

Key findings

  • Attackers are targeting Rust contributors and crate owners with recruitment-style outreach intended to compromise devices and accounts.
  • The lure involves setting up a positive-sounding video interview and then pushing the target to install software (e.g., a “missing audio codec”) or execute a command pasted via the clipboard.
  • Attackers create “new but legitimate-seeming company profiles,” including plausible LinkedIn presences, to pass quick inspection.
  • A June incident used fake interview approaches claiming to be a Singaporean venture capital firm; the outreach was convincing and nearly led to a remote access trojan (RAT) infection.
  • Rust’s ecosystem also experienced a supply-chain incident where a maintainer’s credentials were likely compromised, enabling a popular crate to briefly distribute malware.

Who’s being targeted

  • Commonly targeted roles: Software Developers, Engineering, DevOps, Open Source Program Office (OSPO), Security Awareness, Package Maintainers/Release Managers.
  • Affected industries: Software development, Open source communities, Technology (developer tooling/package ecosystems).
  • Attack channels: linkedin, vishing, email.
  • Impersonated: Recruiter at a legitimate-seeming company (with LinkedIn presence), Singaporean venture capital firm (recruiting outreach).

Awareness takeaways

  • Treat unsolicited recruiter or “opportunity” outreach, especially aimed at maintainers, as a high-risk event and verify the company independently before engaging.
  • Never install software or run commands during an interview/video call to “fix” audio/video problems; stop and verify through your organization’s normal IT process.
  • Recognize that developer account takeover can quickly become a supply-chain incident affecting many downstream users.
  • Use only trusted, approved platforms for calls and collaboration, and be cautious of interview workflows that push you to unfamiliar tools or downloads.

Red flags to watch for

  • Unsolicited recruiting message tied to a new/untested company profile
  • Requests to install extra software during the interview (e.g., an audio codec)
  • Instructions to run a command provided via clipboard during the call
  • Company appears credible at first but basic verification shows issues (e.g., defunct business)
  • Recruiting process leads toward installing/running unexpected software
  • Unsolicited outreach specifically targeting maintainers of widely used packages
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a LinkedIn DM: “We’re a Singaporean venture capital firm, we’d like to interview you about a Rust role.” Looks legit, right? You hop on the video call. A few minutes in, they say, “Your audio’s broken, install this missing codec,” or paste a command and ask you to run it. That’s the move to drop a remote access trojan on your dev box. Rust maintainers have already seen this: fake recruiters with shiny but new LinkedIn profiles, nearly compromising crates so they could ship malware to everyone downstream. Here’s the rule: if a recruiter asks you to install software or run a command during an interview, stop immediately and report it to security, don’t click, don’t run it, just report.

Categories

Similar attacks

Fake Job Video Calls Target Rust Developers

Fake Job Video Calls Target Rust Developers

The Rust project warned of an active social engineering campaign targeting Rust team members and popular crate maintainers. Attackers pose as recruiters or contractors, lure developers into video calls, then trick them into installing software or running pasted code to steal credentials and publish…

September 21, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Teams Helpdesk Vishing Pushes Remote Control Tools

Teams Helpdesk Vishing Pushes Remote Control Tools

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or…

August 31, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026