Skip to content

Commit 0236f55

Browse files
committed
add crates.io phishing post
1 parent dad3816 commit 0236f55

File tree

1 file changed

+22
-0
lines changed

1 file changed

+22
-0
lines changed
Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
+++
2+
path = "2025/09/12/crates-io-phishing-campaign"
3+
title = "crates.io phishing campaign"
4+
authors = ["Rust Security Response WG", "crates.io team"]
5+
aliases = []
6+
+++
7+
8+
We received multiple reports of a phishing campaign targeting crates.io users
9+
(from the `rustfoundation.dev` domain name), mentioning a compromise of our
10+
infrastructure and asking users to authenticate to limit damage to their crates.
11+
12+
These emails are malicious and come from a domain name not controlled by the
13+
Rust Foundation (nor the Rust Project), seemingly with the purpose of stealing
14+
your GitHub credentials. We have no evidence of a compromise of the crates.io
15+
infrastructure.
16+
17+
We are taking steps to get the domain name taken down and to monitor for
18+
suspicious activity on crates.io. Do not follow any links in these emails if you
19+
receive them, and mark them as phishing with your email provider.
20+
21+
If you have any further questions please reach out to [email protected] and
22+

0 commit comments

Comments
 (0)