GHSA-77xj-rrh3-wx3v

Suggest an improvement
Source
https://github.com/advisories/GHSA-77xj-rrh3-wx3v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-77xj-rrh3-wx3v/GHSA-77xj-rrh3-wx3v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-77xj-rrh3-wx3v
Aliases
Published
2026-03-04T20:44:35Z
Modified
2026-03-05T06:11:18Z
Summary
`time_calibrator` was removed from crates.io due to malicious code
Details

It was reported time_calibrator contained malicious code, that would try to upload .env files to a server.

The malicious crate had only 1 version published at 2026-02-28 and no evidence of actual usage. The crate was removed from crates.io and the user account was locked. There were no crates depending on this crate on crates.io.

Rust security response working group thanks Gabriel Silva for finding and reporting this, and thanks to Emily Albini for co-ordinating with the crates.io and infra-admin teams.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-04T20:44:35Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

crates.io / time_calibrator

Package

Name
time_calibrator
View open source insights on deps.dev
Purl
pkg:cargo/time_calibrator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-77xj-rrh3-wx3v/GHSA-77xj-rrh3-wx3v.json"