crates.io phishing attempt
Thanks to my sponsors: Max Bruckner, Mark Tomlin, Raphaël Thériault, Makoto Nakashima, Philipp Angerer, genny, Nereuxofficial, Alex Rudy, Timothée Gerber, Alan O'Donnell, Laine Taffin Altman, Nyefan, Kamran Khan, Hadrien G., Sung Jeon, traxys, Anna M, knutwalker, Olly Swanson, Vladimir and 239 more
Earlier this week, an npm supply chain attack.
It’s turn for crates.io, the main public repository for Rust crates (packages).
The phishing e-mail looks like this:
And it leads to a GitHub login page that looks like this:
Several maintainers received it — the issue is being discussed on GitHub.
The crates.io team has acknowledged the attack and said they’d see if they can do something about it.
No compromised packages have been identified as of yet (Sep 12, 14:10 UTC).
Important links:
Did you know I also make videos? Check them out on YouTube!
Here's another article just for you:
A terminal case of Linux
Has this ever happened to you?
You want to look at a JSON file in your terminal, so you pipe it into jq so you can look at it with colors and stuff.
That’s a useless use of cat.
…oh hey cool bear. No warm-up today huh.
Sure, fine, okay, I’ll read the darn man page for jq… okay it takes
a “filter” and then some files. And the filter we want is.. . which, just
like files, means “the current thing”: