RUSTSEC-2025-0154

Source
https://rustsec.org/advisories/RUSTSEC-2025-0154
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2025-0154.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2025-0154
Aliases
Published
2025-11-04T12:00:00Z
Modified
2026-03-25T08:45:05.193114Z
Summary
`replit_ruspty` was removed from crates.io for malicious code
Details

The OpenSSF Package Analysis project identified 'replit_ruspty' @ 1.0.0 (crates.io) as malicious. Version 2.0.0 was also published with malware.

It is considered malicious because: The package communicates with a domain associated with malicious activity. The package executes one or more commands associated with malicious behavior.

This advisory is to retrospectively document this attack. The download records of the malicious crate are no longer available. The related malicious crates have been deleted.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / replit_ruspty

Package

Name
replit_ruspty
View open source insights on deps.dev
Purl
pkg:cargo/replit_ruspty

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "os": [],
        "functions": [],
        "arch": []
    }
}

Database specific

categories
[
    "malicious"
]
informational
null
cvss
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2025-0154.json"