{"id":"RUSTSEC-2026-0280","summary":"`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code","details":"A new version of the `greentic-setup-dev` crate was published with a variant of\nthe PolinRider malware included that would fire when a project depending on\n`greentic-setup-dev` was opened in Visual Studio Code.\n\nOne malicious version was published on 2026-09-06, approximately 27 hours\nbefore removal. This crate has no dependencies on crates.io. We have no\nevidence that this crate version was downloaded by any actual users, but\nGreentic users should check their systems nonetheless.\n\nThanks to the Research Team at Nextron Systems GmbH for the report.","modified":"2026-09-07T18:23:30.808682339Z","published":"2026-09-07T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/greentic-setup-dev"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0280.html"}],"affected":[{"package":{"name":"greentic-setup-dev","ecosystem":"crates.io","purl":"pkg:cargo/greentic-setup-dev"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.3.34027618345"},{"fixed":"1.3.34027618346-0"}]}],"ecosystem_specific":{"affects":{"functions":[],"arch":[],"os":[]},"affected_functions":null},"database_specific":{"categories":["malicious"],"cvss":null,"informational":null,"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0280.json"}}],"schema_version":"1.9.0"}