{"id":"RUSTSEC-2023-0121","summary":"`libusb1-main` was removed from crates.io for malicious code","details":"This crate was part of a typosquatting malware cluster published by the user\n`Kraded` to run an arbitrary malware payload on Windows hosts.\n\nThis advisory is to retrospectively document this attempted attack. The version\ninformation and download records of the malicious crate are no longer\navailable. The related malicious crates have been yanked, and the malicious\naccount has been banned.","modified":"2026-03-26T06:31:08.685868Z","published":"2023-11-15T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/libusb1-main"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2023-0121.html"}],"affected":[{"package":{"name":"libusb1-main","ecosystem":"crates.io","purl":"pkg:cargo/libusb1-main"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"}]}],"ecosystem_specific":{"affects":{"functions":[],"os":[],"arch":[]},"affected_functions":null},"database_specific":{"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2023-0121.json","cvss":null,"informational":null,"categories":["malicious"]}}],"schema_version":"1.7.5"}