crates.io phishing attempt
Thanks to my sponsors: Geoff Cant, Borys Minaiev, Integer 32, LLC, Matt Heise, Marcin Kołodziej, John VanEnk, Vincent Mutolo, Mateusz Wykurz, Brian L. Troutwine, Kevin Murphy, Mathias Brossard, Ripta Pasay, Lyssieth, Manuel Hutter, asaaki, Michał Bartoszkiewicz, Sawyer Knoblich, Matt Campbell, Kamran Khan, Bob Ippolito and 244 more
Earlier this week, an npm supply chain attack.
It’s turn for crates.io, the main public repository for Rust crates (packages).
The phishing e-mail looks like this:
And it leads to a GitHub login page that looks like this:
Several maintainers received it — the issue is being discussed on GitHub.
The crates.io team has acknowledged the attack and said they’d see if they can do something about it.
No compromised packages have been identified as of yet (Sep 12, 14:10 UTC).
Important links:
Did you know I also make videos? Check them out on PeerTube and also YouTube!
Here's another article just for you:
The curse of strong typing
It happened when I least expected it.
Someone, somewhere (above me, presumably) made a decision. “From now on”, they declared, “all our new stuff must be written in Rust”.
I’m not sure where they got that idea from. Maybe they’ve been reading propaganda. Maybe they fell prey to some confident asshole, and convinced themselves that Rust was the answer to their problems.