RUSTSEC-2026-0280

Source
https://rustsec.org/advisories/RUSTSEC-2026-0280
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0280.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0280
Published
2026-09-07T12:00:00Z
Modified
2026-09-07T18:23:30Z
Summary
`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code
Details

A new version of the greentic-setup-dev crate was published with a variant of the PolinRider malware included that would fire when a project depending on greentic-setup-dev was opened in Visual Studio Code.

One malicious version was published on 2026-09-06, approximately 27 hours before removal. This crate has no dependencies on crates.io. We have no evidence that this crate version was downloaded by any actual users, but Greentic users should check their systems nonetheless.

Thanks to the Research Team at Nextron Systems GmbH for the report.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / greentic-setup-dev

Package

Name
greentic-setup-dev
View open source insights on deps.dev
Purl
pkg:cargo/greentic-setup-dev

Affected ranges

Type
SEMVER
Events
Introduced
1.3.34027618345
Fixed
1.3.34027618346-0

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "arch": [],
        "functions": [],
        "os": []
    }
}

Database specific

categories
[
    "malicious"
]
cvss
null
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0280.json"