{"id":"RUSTSEC-2026-0171","summary":"`logflux` was removed from crates.io for malicious code","details":"The `logflux` crate attempted to download and run a malicious payload on the\nuser's machine.\n\nThe malicious crate had 1 version published on 2026-04-26, approximately 1\nmonth before removal, and had no evidence of actual usage. This crate had no\ndependencies on crates.io.\n\nThanks to Paweł Bis for discovering and reporting this crate!\n\nThis appears to have been part of a campaign targeting people applying for Rust\njobs. Please be careful with take-home assignments, especially if they ask you\nto use specific dependencies.","modified":"2026-06-04T20:00:04.181813760Z","published":"2026-06-03T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/logflux"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0171.html"}],"affected":[{"package":{"name":"logflux","ecosystem":"crates.io","purl":"pkg:cargo/logflux"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"}]}],"ecosystem_specific":{"affects":{"functions":[],"arch":[],"os":[]},"affected_functions":null},"database_specific":{"cvss":null,"informational":null,"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0171.json","categories":["malicious"]}}],"schema_version":"1.7.5"}