[Pre-RFC] DNS domains as package namespaces
Rust Internals [Unofficial]
April 27, 2026
> NPM already had a wave of supply chain attacks via custom domains with lapsed registration. An attacker would register the domain immediately after it expires, then use the account recovery via email to take control of the account.
NPM doesn't support domains as package namespaces, account takeover affects packages regardless of whether they're namespaced or not, and package namespaces are unrelated to security measures put in place to prevent account takeover.
Discussion in the ATmosphere