crates.io phishing attempt
Thanks to my sponsors: Ben Wishovich, Dom, Twan Walpot, Daniel Silverstone, Philipp Angerer, Vladimir, avborhanian, me, Justy, Nyefan, The0x539, Mathew Haji, Brandon Piña, Kamran Khan, SeniorMars, Victor Song, Lawrence Bethlenfalvy, Jeff Crocker, Marcin Kołodziej, eliferrous and 253 more
Earlier this week, an npm supply chain attack.
It’s turn for crates.io, the main public repository for Rust crates (packages).
The phishing e-mail looks like this:
And it leads to a GitHub login page that looks like this:
Several maintainers received it — the issue is being discussed on GitHub.
The crates.io team has acknowledged the attack and said they’d see if they can do something about it.
No compromised packages have been identified as of yet (Sep 12, 14:10 UTC).
Important links:
Did you know I also make videos? Check them out on PeerTube and also YouTube!
Here's another article just for you:
Peeking inside a Rust enum
During a recent Rust Q&A Session on my twitch
channel, someone asked a question that
seemed simple: why are small string types, like SmartString or SmolStr,
the same size as String, but small vec types, like SmallVec, are larger
than Vec?
Now I know I just used the adjective simple, but the truth of the matter is: to understand the question, we’re going to need a little bit of background.