Skip to content
AI News HubLIVE
Source content · Analysis pending1 min read

Be alert: targeted attacks on prominent Rustaceans

Summary

Be alert: targeted attacks on prominent Rustaceans Important warning from Adam Harvey and the crates security team: We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware. A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard). Last month this trick was used in a successful supply chain attack against the array ref crate, among others. Any piece of software that depen…

Be alert: targeted attacks on prominent Rustaceans
Report an error

The correction channel is not available yet. You can copy the article reference below for later.

Correction instructions
Read article

Be alert: targeted attacks on prominent Rustaceans

Simon Willison’s Weblog

Subscribe

17th September 2026 - Link Blog

Be alert: targeted attacks on prominent Rustaceans. Important warning from Adam Harvey and the crates security team:

We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware.

A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard).

Last month this trick was used in a successful supply chain attack against the array ref crate, among others.

Any piece of software that depends on open source (which is almost every piece of software) has a network of human beings who are potential attack vectors - everyone with publishing rights to any of the packages in the dependency network for that software.

I guess our best defense right now is dependency cooldowns - giving new package releases a few days before upgrading to them, in the hope that supply chain attacks like this will be spotted by someone else.

Recent articles

Generating running routes with GPT-6 Astra and ChatGPT Work - 12th September 2026

OpenAI agents attacked RubyGems back in May - 12th September 2026

Some thoughts on the Navier–Stokes Millennium Prize Problem - 8th September 2026

This is a link post by Simon Willison, posted on 17th September 2026.

open-source 321

security 637

rust 114

supply-chain 22

dependency-cooldowns 5

Monthly briefing

Sponsor me for $10/month and get a curated email digest of the month's most important LLM developments.

Pay me to send you less!

Sponsor & subscribe

Disclosures

Colophon

©

2002

2003

2004

2005

2006

2007

2008

2009

2010

2011

2012

2013

2014

2015

2016

2017

2018

2019

2020

2021

2022

2023

2024

2025

2026

Key points and analysis

Article intelligence

EngineersIntermediate

Key points

  • AI generation is temporarily unavailable; this entry was preserved with deterministic fallback metadata.
  • Be alert: targeted attacks on prominent Rustaceans Important warning from Adam Harvey…

Highlights and analysis are generated automatically and may contain errors. Check the original source.