crates.io phishing attempt
Thanks to my sponsors: Zalán Bálint Lévai, Marty Penner, asaaki, Tomáš Šedovič, Braidon Whatley, Édomaur odéon, Nyefan, std__mpa, Dominik Wagner, prairiewolf, Carson Page, Raine Godmaire, AdrianEddy, Santiago Lema, Jeff Crocker, Marc-Andre Giroux, Ian McLinden, Yuriy Taraday, Björn Marschollek, Benjamin Röjder Delnavaz and 241 more
Earlier this week, an npm supply chain attack.
It’s turn for crates.io, the main public repository for Rust crates (packages).
The phishing e-mail looks like this:
And it leads to a GitHub login page that looks like this:
Several maintainers received it — the issue is being discussed on GitHub.
The crates.io team has acknowledged the attack and said they’d see if they can do something about it.
No compromised packages have been identified as of yet (Sep 12, 14:10 UTC).
Important links:
Did you know I also make videos? Check them out on YouTube!
Here's another article just for you:
What's in the box?
Here’s a sentence I find myself saying several times a week:
…or we could just box it.
There’s two remarkable things about this sentence.
The first, is that the advice is very rarely heeded, and instead, whoever I just said it to disappears for two days, emerging victorious, basking in the knowledge that, YES, the compiler could inline that, if it wanted to.