SyncAI.news, a Varaisys broadcasting
Be alert: targeted attacks on prominent Rustaceans
SW

Simon Willison's Weblog

· 1 min read

AnalysisSimon Willison's Weblog

Be alert: targeted attacks on prominent Rustaceans

Be alert: targeted attacks on prominent Rustaceans

Important warning from Adam Harvey and the crates security team:

We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware.

A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard).

Last month this trick was used in a successful supply chain attack against the array ref crate, among others.

Any piece of software that depends on open source (which is almost every piece of software) has a network of human beings who are potential attack vectors - everyone with publishing rights to any of the packages in the dependency network for that software.

I guess our best defense right now is dependency cooldowns - giving new package releases a few days before upgrading to them, in the hope that supply chain attacks like this will be spotted by someone else.

Original source

This story was published by Simon Willison's Weblog. SyncAI.news shows a preview; the complete article is on the publisher's site.

Read the full story on simonwillison.net

Similar News