criticalVulnerability

GHSA-382q-fpqh-29f7

It appeared to be typosquatting existing crate [`polymarket-client-sdk`](https://crates.io/crates/polymarket-client-sdk) (`clients` vs `client`) and attempting to steal credentials from local files. The malicious crate had 6 versions published on 2026-02-05 and had been downloaded only 59 times. There were no crates depending on this crate on crates.io. Polymarket thanks [Socket.dev](https://socket.dev/) for detecting and reporting this to the crates.io team!

Properties

ghsa_id
GHSA-382q-fpqh-29f7
severity
critical
summary
`polymarket-clients-sdk` was removed from crates.io for malicious code
cve_id
GHSA-382q-fpqh-29f7
is_ghsa_only
true
ghsa_published
2026-02-06T20:56:19Z
source_url
https://github.com/advisories/GHSA-382q-fpqh-29f7
ghsa_updated
2026-02-06T20:56:21Z

Related Entities (2)

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]rust/polymarket-clients-sdk

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-382q-fpqh-29f7 — Ninja Signal Threat Intelligence | Ninja Signal