产品与商业 4.0 · 优秀 2026-09-17 · 文章

Be alert: targeted attacks on prominent Rustaceans

Willison 9 月 17 日转 Rust crates 安全团队的警报:有人在针对 rust-lang 成员和流行 crate 的 maintainer 做定向社工套路是先约看起来正面的视频通话(工作项目合同机会都行),让目标装一个缺了的音频 codec之类的东西,或把一段命令塞进剪贴板让你执行,最终拿到发布权限8 月那次针对 arrayref crate 的供应链攻击就是同一手法文章给出的当下唯一可执行防御是 dependency cooldowns:给新版本几天缓冲再升级,争取让攻击被其他人先发现任何依赖开源生态的项目都跑不掉这条风险链你的代码背后是一张人构成的信任图

打开原文回到归档

Be alert: targeted attacks on prominent Rustaceans

中文摘要

Willison 9 月 17 日转 Rust crates 安全团队的警报:有人在针对 rust-lang 成员和流行 crate 的 maintainer 做定向社工套路是先约看起来正面的视频通话(工作项目合同机会都行),让目标装一个缺了的音频 codec之类的东西,或把一段命令塞进剪贴板让你执行,最终拿到发布权限8 月那次针对 arrayref crate 的供应链攻击就是同一手法文章给出的当下唯一可执行防御是 dependency cooldowns:给新版本几天缓冲再升级,争取让攻击被其他人先发现任何依赖开源生态的项目都跑不掉这条风险链你的代码背后是一张人构成的信任图

English Abstract

Simon Willison's September 17 link post relays a Rust crates security team alert: an ongoing campaign targets rust-lang members and maintainers of popular crates with social engineering. The pattern is to schedule a positive-sounding video call (job, project, contract opportunity), then get the target to install a 'missing audio codec' or to execute a command the attacker pasted to the clipboard, ultimately gaining publish rights. The August supply-chain attack on the arrayref crate used the same playbook. The only currently executable defense the post names is dependency cooldowns give new versions a few days before upgrading, hoping the attack gets spotted elsewhere first. Any project leaning on the open-source ecosystem inherits this risk chain: behind your code is a trust graph made of people.

为什么值得关注

Rust crates 团队警告:针对维护者视频通话社工装 codec / 剪贴板命令拿发布权限dependency cooldown 是当下唯一可执行防御

Obsidian 证据摘要

来源: OpenClaw定时任务/AK-RSS-Digest(89源精选)/2026-09-21-AK-RSS-Digest(89源精选).md + 对应 evidence-2026-09-21 文件