External Publication
Visit Post

[Pre-RFC] DNS domains as package namespaces

Rust Internals [Unofficial] April 27, 2026
Source
> NPM already had a wave of supply chain attacks via custom domains with lapsed registration. An attacker would register the domain immediately after it expires, then use the account recovery via email to take control of the account. NPM doesn't support domains as package namespaces, account takeover affects packages regardless of whether they're namespaced or not, and package namespaces are unrelated to security measures put in place to prevent account takeover.

Discussion in the ATmosphere

Loading comments...