crates.io phishing attempt
Thanks to my sponsors: Marty Penner, Astrid, Richard Pringle, asaaki, Henrik Tudborg, Angelo, xales, Dirkjan Ochtman, Jake Demarest-Mays, Björn Marschollek, Marie Janssen, Vladimir, Matthias Zepper, Daniel Silverstone, rektide, Hamilton Chapman, Olly Swanson, Lyrenhex, Max von Forell, Dylan Anthony and 241 more
Earlier this week, an npm supply chain attack.
It’s turn for crates.io, the main public repository for Rust crates (packages).
The phishing e-mail looks like this:
And it leads to a GitHub login page that looks like this:
Several maintainers received it — the issue is being discussed on GitHub.
The crates.io team has acknowledged the attack and said they’d see if they can do something about it.
No compromised packages have been identified as of yet (Sep 12, 14:10 UTC).
Important links:
Did you know I also make videos? Check them out on YouTube!
Here's another article just for you:
Remote development with Rust on fly.io
Disclaimer:
At the time of this writing, I benefit from the fly.io “Employee Free Tier”. I don’t pay for side projects hosted there “within reasonable limits”. The project discussed here qualifies for that.
Why you might want a remote dev environment
Fearmongering aside — and Cthulhu knows there’s been a bunch, since this unfortunate tweet — there’s a bunch of reasons to want a remote dev environment.