criticalVulnerability
GHSA-382q-fpqh-29f7
It appeared to be typosquatting existing crate [`polymarket-client-sdk`](https://crates.io/crates/polymarket-client-sdk) (`clients` vs `client`) and attempting to steal credentials from local files. The malicious crate had 6 versions published on 2026-02-05 and had been downloaded only 59 times. There were no crates depending on this crate on crates.io. Polymarket thanks [Socket.dev](https://socket.dev/) for detecting and reporting this to the crates.io team!
Properties
- ghsa_id
- GHSA-382q-fpqh-29f7
- severity
- critical
- summary
- `polymarket-clients-sdk` was removed from crates.io for malicious code
- cve_id
- GHSA-382q-fpqh-29f7
- is_ghsa_only
- true
- ghsa_published
- 2026-02-06T20:56:19Z
- source_url
- https://github.com/advisories/GHSA-382q-fpqh-29f7
- ghsa_updated
- 2026-02-06T20:56:21Z
Related Entities (2)
REPORTED_BY (1)
→[Source]GitHub Advisory Database
AFFECTS (1)
→[Software]rust/polymarket-clients-sdk
Explore deeper with Ninja Signal's threat intelligence graph