crates.io phishing attempt
Thanks to my sponsors: Geoff Cant, Wyatt Herkamp, C J Silverio, Joshua Roesslein, budrick, frankwang, Reto Trappitsch, Henrik Tudborg, Eugene Bulkin, Borys Minaiev, Dimitri Merejkowsky, Malik Bougacha, Mike English, Björn Marschollek, Marcus Griep, Jeff Crocker, Guillaume E, Mathias Brossard, Enrico Zschemisch, Astrid and 246 more
Earlier this week, an npm supply chain attack.
It’s turn for crates.io, the main public repository for Rust crates (packages).
The phishing e-mail looks like this:
And it leads to a GitHub login page that looks like this:
Several maintainers received it — the issue is being discussed on GitHub.
The crates.io team has acknowledged the attack and said they’d see if they can do something about it.
No compromised packages have been identified as of yet (Sep 12, 14:10 UTC).
Important links:
Did you know I also make videos? Check them out on PeerTube and also YouTube!
Here's another article just for you:
The virtue of unsynn
Addressing the rumors
There have been rumors going around, in the Reddit thread for facet, my take on reflection in Rust, which happened a bit too early, but here we are, cat’s out of the bag, let’s talk about it!
Rumors that I, podcaster/youtuber fasterthanlime, want to kill serde, serialization / deserialization framework loved by many and which contributed greatly to Rust’s success, and I just wanted to address those rumors and say that…