On Sept. 17, 2026, Adam Harvey on behalf of the crates.io team and the security response working group warned of an ongoing campaign targeting rust-lang contributors and owners of popular crates. Attackers are arranging seemingly legitimate video calls - for jobs, projects, or contract opportunities - then using those sessions as vectors to get targets to install software (for example, a fake missing audio codec) or to execute commands (for example, by placing malicious commands on the clipboard). The campaign relies on newly created but credible company profiles and plausible LinkedIn presences to survive cursory scrutiny, with the ultimate goal of compromising devices and accounts so they can be used to publish malware.
The recommended response is heightened caution: treat cold outreach with skepticism, prefer calls on platforms you already trust, and whenever possible be the one to initiate the meeting on a familiar service. Audit your accounts now - enable multi-factor authentication, check for unexpected logins or session activity, and verify that recovery and authorizations are intact. For help with crates.io account issues, contact [email protected]; for other security concerns, contact [email protected].
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.