Rust 生态面临定向攻击,开发者需警惕供应链风险
Be alert: targeted attacks on prominent Rustaceans
Rust 开发者注意了,最近有针对我们社区成员的定向攻击,通过视频通话诱导安装东西,已经成功攻击了 array ref 等包,大家要小心。
crates 安全团队警告称,针对 Rust 生态成员的定向攻击活动正在持续,攻击者通过视频通话诱骗目标安装恶意软件或执行命令。上月该手段已成功攻击 array ref 等流行包。依赖开源软件的任何项目都存在供应链风险,建议对新包发布实施依赖冷却期。
Be alert: targeted attacks on prominent Rustaceans
Be alert: targeted attacks on prominent Rustaceans Important warning from Adam Harvey and the crates security team: We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware. A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard). Last month this trick was used in a successful supply chain attack against the array ref crate , among others. Any piece of software that depends on open source (which is almost every piece of software) has a network of human beings who are potential attack vectors - everyone with publishing rights to any of the packages in the dependency network for that software. I guess our best defense right now is dependency cooldowns - giving new package releases a few days before upgrading to them, in the hope that supply chain attacks like this will be spotted by someone else. Tags: open-source , security , rust , supply-chain , dependency-cooldowns