The recent Rust maintainer incidents are all one campaign
Assessment
Coverage of the Rust advisory tends to present the recent events as a connected campaign: the September fake-video-call attacks, an earlier June 2026 incident targeting prominent Rust developers, and the August 2026 compromise of the arrayref crate (and, per reporting, internment and append-only-vec) that reportedly ran a remote payload at build time. But the Rust project's own advisory states plainly: 'At this moment we do not know if these are all a part of the same campaign.' The incidents share a general flavour (targeting Rust maintainers, social engineering) and may well be linked, but the maintainers themselves have not established that they are one operation by one actor. Treating them as a single confirmed campaign asserts a connection the primary source declines to make.
Where this claim appeared
The Rust Programming Language Blog · 2026-09-17
https://blog.rust-lang.org/2026/09/17/targeted-attacks/What “Unverified” means
Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.
2 of 5 · rating scale
Assessed in
Rust maintainers targeted via fake-recruiter video calls — a supply-chain attack through the front door of trustThink this assessment is wrong? Report an error.