Live data from Hacker News

Crates.io phishing attempt

fasterthanli.me

41–50 of 83 posts

Re: Crates.io phishing attempt

#41
post #33

If you get a message (text, email or call), it's best to not trust the contents of the message until you verify it by logging in or whatever yourself. If crates.io says you have a problem, close the email and go to crates.io yourself. If your bank calls you, hang up and log in or call their support number yourself. Don't trust anyone contacting you for sensitive stuff

Definitely. I get scammers calling me from a caller id that claims to be my bank asking about suspicious charges, and they know my name and have my account info, but they ask for my full credit card number to "verify" it. Yet, they give different suspicious charges every time you ask. The worst part is that when I call the bank to see if its legit, they are much less pleasant to deal with than the scammers...

I've stopped trying to call - if I think there's a problem I go into my local branch. Much harder to put me on hold for 40 minutes and then hang up in person.

Re: Crates.io phishing attempt

#42
That's an exceptionally well crafted phishing email and landing page. It looks so real! Even the URL looks legit - github.rustfoundation.dev (the real URL is rustfoundation.org).

Btw, if you go to https://rustfoundation.dev right now it says in meme format: Virgin npm devs falling for phishing (sleepy doge) vs Chad Rust devs (shredded doge).

As chad as Rust devs supposedly are, something tells me at least a few of them are going to fall for this attack.

Re: Crates.io phishing attempt

#43

That's an exceptionally well crafted phishing email and landing page. It looks so real! Even the URL looks legit - github.rustfoundation.dev (the real URL is rustfoundation.org). Btw, if you go to https://rustfoundation.dev right now it says in meme format: Virgin npm devs falling for phishing (sleepy doge) vs Chad Rust devs (shredded doge). As chad as Rust devs supposedly are, something tells me at least a few of th…

[deleted]

Re: Crates.io phishing attempt

#44

If you get a message (text, email or call), it's best to not trust the contents of the message until you verify it by logging in or whatever yourself. If crates.io says you have a problem, close the email and go to crates.io yourself. If your bank calls you, hang up and log in or call their support number yourself. Don't trust anyone contacting you for sensitive stuff

> If your bank calls you, hang up and log in or call their support number yourself.

And don't trust the number you see on Google. Google is known to show scammers' phone numbers in featured snippets or in their new "AI Mode". Click on the link and make sure it's the correct site before trusting the number.

Re: Crates.io phishing attempt

#46

If you get a message (text, email or call), it's best to not trust the contents of the message until you verify it by logging in or whatever yourself. If crates.io says you have a problem, close the email and go to crates.io yourself. If your bank calls you, hang up and log in or call their support number yourself. Don't trust anyone contacting you for sensitive stuff

Always good advice for anything. A variation of this is that you should also not answer the negative: that you definitely did not do something, if someone asks you that on a phone call. This is meant to spread harm to others.

I was speaking to a pharmacist yesterday. Apparently certain pharmacy insurance companies in the US have set up call centers that randomly call people and ask.

"We are from the fraud check department. Did you ask for receiving XYZ medication that your insurance paid $$$$$$ for?". The guy who does who's salary is an order of magnitude smaller, immediately panics and denies he ever asked for XYZ, even though they are obviously taking the medication. The purpose is of-course for pharmacy insurance companies to challenge/deny claims for on ALL XYZ orders the pharmacy made.

Of course checking insurance payouts is a hassle so most people reach for panic first and shortly thereafter denial.

Re: Crates.io phishing attempt

#47

If you get a message (text, email or call), it's best to not trust the contents of the message until you verify it by logging in or whatever yourself. If crates.io says you have a problem, close the email and go to crates.io yourself. If your bank calls you, hang up and log in or call their support number yourself. Don't trust anyone contacting you for sensitive stuff

The spammy calls I've gotten lately are for "tax help from the IRS" ... I really feel there's a special place in hell for people that do that.

Re: Crates.io phishing attempt

#48
post #13

Earlier quoted context omitted.

People realized that past phishing attempts were quite badly constructed and a well constructed one is actually really easy to fall for.

> and a well constructed one is actually really easy to fall for It really shouldn't though, and something you need to be personally responsible for. If it's still possible in 2025 for you to fall for phishing attempts, you're missing something, something that starts with a p and ends with a assword manager .

You must be joking. When I try to log in on Outlook I get redirected to 'microsoftonline.com' (suspicious), when I log in on Wikipedia it sends me to something called 'wikimedia.org' (typo squatter?). How the hell am I supposed to know whether npmjs.help or rustfoundation.dev are _not_ the official domains of those projects?

Re: Crates.io phishing attempt

#49
post #46

If you get a message (text, email or call), it's best to not trust the contents of the message until you verify it by logging in or whatever yourself. If crates.io says you have a problem, close the email and go to crates.io yourself. If your bank calls you, hang up and log in or call their support number yourself. Don't trust anyone contacting you for sensitive stuff

Always good advice for anything. A variation of this is that you should also not answer the negative: that you definitely did not do something, if someone asks you that on a phone call. This is meant to spread harm to others. I was speaking to a pharmacist yesterday. Apparently certain pharmacy insurance companies in the US have set up call centers that randomly call people and ask. "We are from the fraud check depar…

That's just icky.

Re: Crates.io phishing attempt

#50

Earlier quoted context omitted.

Let's say someone falls for this. What happens next, when they become the business account secondary user?

I added to my comment, but when you call the number, you talk to the attacker and they ask you questions about you and your account. Maybe they try to buy crypto with it or they prime you to go to some attack website and use your paypal account to buy something.

oh no, not at all.

They will attempt to get you to install AnyDesk or some kind of remote software and then pwn your computer. They will remote in "to fix the hack" because your computer is obviously infected with a virus. Then either just steal your money from your bank account or etc.

Post reply on HN