{"id":"GHSA-p5vf-5754-x7p3","summary":"`polymarket-client-sdks` was removed from crates.io for malicious code","details":"It appeared to be typosquatting existing crate [`polymarket-client-sdk`](https://crates.io/crates/polymarket-client-sdk) (`sdks` vs `sdk`) and attempting to steal credentials from local files.\n\nThe malicious crate had 1 version published on 2026-02-09 and had been downloaded only 33 times. There were no crates depending on this crate on crates.io.\n\nThanks to Roland Peelen for finding and reporting this to the crates.io team!","aliases":["RUSTSEC-2026-0011"],"modified":"2026-02-14T08:26:18.838806Z","published":"2026-02-13T21:02:38Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-02-13T21:02:38Z","nvd_published_at":null,"cwe_ids":["CWE-506"]},"references":[{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0011.html"}],"affected":[{"package":{"name":"polymarket-client-sdks","ecosystem":"crates.io","purl":"pkg:cargo/polymarket-client-sdks"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-p5vf-5754-x7p3/GHSA-p5vf-5754-x7p3.json"}}],"schema_version":"1.9.0"}