Crates.io phishing attempt
fasterthanli.me
Crates.io phishing attempt
1–10 of 83 posts
Re: Crates.io phishing attempt
#2Re: Crates.io phishing attempt
#3https://blog.rust-lang.org/2025/09/12/crates-io-phishing-cam...
Re: Crates.io phishing attempt
#4The only phishing I can see that would be extremely hard to detect are browser extension injections (either in extension window or page replacement) so the domain is legitimate.
Re: Crates.io phishing attempt
#5Why does it seem like phishing is popular again? Maybe bad actors forgot how gullible humans were? I get phishing attempts nearly daily via email or sms and I honestly thought “Who would fall for this?” every time one came in. The only phishing I can see that would be extremely hard to detect are browser extension injections (either in extension window or page replacement) so the domain is legitimate.
Re: Crates.io phishing attempt
#6Why does it seem like phishing is popular again? Maybe bad actors forgot how gullible humans were? I get phishing attempts nearly daily via email or sms and I honestly thought “Who would fall for this?” every time one came in. The only phishing I can see that would be extremely hard to detect are browser extension injections (either in extension window or page replacement) so the domain is legitimate.
Was it ever not popular? Looking at my spam box, I receive countless of phishing attempts per week, and doing some quick queries of the total count over time, it seems to more or less been the same for the last 2-3 years at the very least.
I'm not sure why it's such big news all of a sudden, probably because it recently succeeded against a developer of some popular npm packages?
I think most people either have the phishing emails flagged, so they never see them. The ones that get seen, get ignored as obvious phishing. And for the ones that click the link, their password manager would stop them from entering their detail. And then you have the final 0.0001% who never protected themselves, and were tired/stressed at that very moment, and fell for it.
So I guess ultimately it's bound to become news every now and then, until everyone finally got the memo to get a proper password manager that don't show accounts that don't belong to the domain.
Re: Crates.io phishing attempt
#7Why does it seem like phishing is popular again? Maybe bad actors forgot how gullible humans were? I get phishing attempts nearly daily via email or sms and I honestly thought “Who would fall for this?” every time one came in. The only phishing I can see that would be extremely hard to detect are browser extension injections (either in extension window or page replacement) so the domain is legitimate.
It feels like it has become significantly more prevalent in the last couple years (tracking the rise of "business email compromise" being a term-of-art).
Re: Crates.io phishing attempt
#8Why does it seem like phishing is popular again? Maybe bad actors forgot how gullible humans were? I get phishing attempts nearly daily via email or sms and I honestly thought “Who would fall for this?” every time one came in. The only phishing I can see that would be extremely hard to detect are browser extension injections (either in extension window or page replacement) so the domain is legitimate.
You can further appeal to developers’ geeky hearts by not making language mistakes and actually using verbiage present in real emails as sent by them.
You can exploit recent supply chain attacks and the sense of urgency and panic that developer blogs have created by pressing for even more urgency.
Seems like this does work. Don’t worry, when they actually target you, you’ll be caught.
Re: Crates.io phishing attempt
#9Why does it seem like phishing is popular again? Maybe bad actors forgot how gullible humans were? I get phishing attempts nearly daily via email or sms and I honestly thought “Who would fall for this?” every time one came in. The only phishing I can see that would be extremely hard to detect are browser extension injections (either in extension window or page replacement) so the domain is legitimate.
Re: Crates.io phishing attempt
#10Why does it seem like phishing is popular again? Maybe bad actors forgot how gullible humans were? I get phishing attempts nearly daily via email or sms and I honestly thought “Who would fall for this?” every time one came in. The only phishing I can see that would be extremely hard to detect are browser extension injections (either in extension window or page replacement) so the domain is legitimate.