RUSTSEC-2026-0281

Source
https://rustsec.org/advisories/RUSTSEC-2026-0281
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0281.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0281
Published
2026-09-07T12:00:00Z
Modified
2026-09-07T18:23:30Z
Summary
`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code
Details

A new version of the greentic-setup crate was published with a variant of the PolinRider malware included that would fire when a project depending on greentic-setup was opened in Visual Studio Code.

One malicious version was published on 2026-09-06, approximately 27 hours before removal. This crate is depended on by four other crates in the Greentic ecosystem, namely greentic-start, greentic-start-dev, greentic-operator, and greentic-operator-dev. We have no evidence that this crate version was downloaded by any actual users, but Greentic users should check their systems nonetheless.

Thanks to the Research Team at Nextron Systems GmbH for the report.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / greentic-setup

Package

Name
greentic-setup
View open source insights on deps.dev
Purl
pkg:cargo/greentic-setup

Affected ranges

Type
SEMVER
Events
Introduced
1.3.1-dev.34027618345
Fixed
1.3.1-dev.34027618345.0

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "arch": [],
        "functions": [],
        "os": []
    }
}

Database specific

categories
[
    "malicious"
]
cvss
null
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0281.json"