警告:针对知名 Rust 开发者的定向供应链攻击
原标题:Be alert: targeted attacks on prominent Rustaceans
AI 摘要
Adam Harvey 与 crates 安全团队发布警告,称存在一场针对 rust-lang 成员及热门 crate 所有者的持续攻击活动,攻击者通过伪装成工作、项目或合同机会的视频通话,诱导目标安装恶意软件(如伪装成缺失的音频编解码器)或执行剪贴板中的命令,以劫持其账户发布恶意软件。上月该手法已成功用于对 arrayref crate 等目标的供应链攻击。Simon Willison 指出,任何依赖开源软件的软件都面临由人类发布者构成的攻击面,目前最佳防御是依赖冷却期,即新版本发布后等待数天再升级,以期他人先发现此类攻击。
正文节选
17th September 2026 - Link Blog Be alert: targeted attacks on prominent Rustaceans. Important warning from Adam Harvey and the crates security team: We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware. A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector