Subscribe Sign in

Rustaceans warned of job interviews with a malicious payload

1 min read Rewritten in plain language

Security

Show what we removed Rules applied: A6 C2×2 D3×4 D4×4 E3 F2×7 all 30 rules
  • Attackers are courting crate owners with plausible company profiles and booby-trapped recruitment calls.
  • Posting to the Rust blog, security-focused software engineer Adam Harvey said the tactics resemble those used in North Korean fake recruiter campaigns.
  • In June, Rust developers were targeted with fake interview approaches purporting to come from a Singaporean venture capital firm.
  • The advisory said North Korean operators had used fake job interviews to compromise more than 30,000 devices and steal over $10 million.

4 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

The Rust project has said attackers appear to be targeting its contributors and crate owners in an attempt to compromise their devices and accounts, potentially allowing malware to be distributed through its package ecosystem. Separately, Rust's package ecosystem suffered a supply chain attack in August.

Headline check

There is nothing in this headline a machine can check against the report: no figure, no name and no quotation.

Nothing was measured here, so nothing is claimed. How this is checked

Attackers are courting crate owners with plausible company profiles and booby-trapped recruitment calls.

The Rust project has said that attackers appear to be targeting its contributors and crate owners in an attempt to compromise their devices and accounts, potentially allowing malware to be distributed through its package ecosystem.

Posting to the Rust blog, security-focused software engineer Adam Harvey said the tactics resemble those used in North Korean fake recruiter campaigns.

The warning follows several attacks targeting the Rust community over the summer.

In June, Rust developers were targeted with fake interview approaches purporting to come from a Singaporean venture capital firm. Matt Mastracci, who maintains packages on Rust's crates.io registry, said the supposedly recruiting business turned out to be defunct.

The advisory said North Korean operators had used fake job interviews to compromise more than 30,000 devices and steal over $10 million.

Shortened to 1 minute of reading, this version reads 6 on the Niral Score.

You are reading our version, not theirs. This is The Register's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 9 10 81 -0.1 40
Mundane Readneutralized from The Register 7.2 10 81 -0.1 40

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works