Supply chain attach on cargo crates.io? is your publish credential safe?

just read this news, I wonder how bad is it? are you affected by this? the crates seems to have large volume of downloads?

The report on the Rust blog

I find it suspicious that the owner's GitHub profile, including all the repos, has disappeared.
Is this a precaution by GitHub or was the malicious code hosted there too, in the official sources?

oh, I didn't know that. it's very peculiar indeed.

maybe the owner's other credentials got compromised, not just the crate publishing token? that's kind of scary to think about, like, one's online identity could get erased completely.

They found the problem pretty quickly. Has anybody reported they were compromised in this "hack".
Maybe our security is "good enough".