RUSTSEC-2026-0040

Source
https://rustsec.org/advisories/RUSTSEC-2026-0040
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0040.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0040
Published
2026-03-14T12:00:00Z
Modified
2026-03-17T22:45:08.656352Z
Summary
`tracing-ethers` was removed from crates.io due to malicious code
Details

The tracing-ethers crate attempted to exfiltrate ssh keys to an app hosted on vercel.app

The malicious crate had 9 version published on 2026-03-09 approximately 5 days before removal and had no evidence of actual downloads. There were no crates depending on this crate on crates.io.

Thanks to the user killa for reporting this malicious crate.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / tracing-ethers

Package

Name
tracing-ethers
View open source insights on deps.dev
Purl
pkg:cargo/tracing-ethers

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "arch": [],
        "functions": [],
        "os": []
    }
}

Database specific

categories
[
    "malicious"
]
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0040.json"
informational
null
cvss
null