RUSTSEC-2026-0171

Source
https://rustsec.org/advisories/RUSTSEC-2026-0171
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0171.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0171
Published
2026-06-03T12:00:00Z
Modified
2026-06-04T20:00:04Z
Summary
`logflux` was removed from crates.io for malicious code
Details

The logflux crate attempted to download and run a malicious payload on the user's machine.

The malicious crate had 1 version published on 2026-04-26, approximately 1 month before removal, and had no evidence of actual usage. This crate had no dependencies on crates.io.

Thanks to Paweł Bis for discovering and reporting this crate!

This appears to have been part of a campaign targeting people applying for Rust jobs. Please be careful with take-home assignments, especially if they ask you to use specific dependencies.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / logflux

Package

Name
logflux
View open source insights on deps.dev
Purl
pkg:cargo/logflux

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "arch": [],
        "functions": [],
        "os": []
    }
}

Database specific

categories
[
    "malicious"
]
cvss
null
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0171.json"