crates.io phishing attempt
Thanks to my sponsors: Brandon Piña, Max von Forell, Ian McLinden, Laine Taffin Altman, Björn Marschollek, Aiden Scandella, Mark Old, Walther, me, Menno Finlay-Smits, Chris Biscardi, Colin VanDervoort, Hadrien G., Yufan Lou, Justin Ossevoort, Pete Bevin, Kai Kaufman, Antoine PESTEL-ROPARS, Chris Emery, Adam Gutglick and 252 more
Earlier this week, an npm supply chain attack.
It’s turn for crates.io, the main public repository for Rust crates (packages).
The phishing e-mail looks like this:
And it leads to a GitHub login page that looks like this:
Several maintainers received it — the issue is being discussed on GitHub.
The crates.io team has acknowledged the attack and said they’d see if they can do something about it.
No compromised packages have been identified as of yet (Sep 12, 14:10 UTC).
Important links:
Did you know I also make videos? Check them out on PeerTube and also YouTube!
Here's another article just for you:
Frustrated? It's not you, it's Rust
Learning Rust is… an experience. An emotional journey. I’ve rarely been more frustrated than in my first few months of trying to learn Rust.
What makes it worse is that it doesn’t matter how much prior experience you have, in Java, C#, C or C++ or otherwise - it’ll still be unnerving.
In fact, more experience probably makes it worse! The habits have settled in deeper, and there’s a certain expectation that, by now, you should be able to get that done in a shorter amount of time.