criticalVulnerability

GHSA-5pmp-jpcf-pwx6

This is part of an ongoing campaign to attempt to typosquat crates in the [`polymarket-client-sdk`](https://crates.io/crates/polymarket-client-sdk) ecosystem to exfiltrate user credentials. The malicious crate had 1 version published on 2026-02-24 approximately 4 hours before removal and had no evidence of actual downloads. There were no crates depending on this crate on crates.io. The crates.io team advises anyone developing with Polymarket to review dependencies carefully. We are investigating ways to mitigate this attacker who appears to be very motivated to steal Polymarket credentials.

Properties

ghsa_id
GHSA-5pmp-jpcf-pwx6
severity
critical
summary
`tracing-check` was removed from crates.io for malicious code
cve_id
GHSA-5pmp-jpcf-pwx6
is_ghsa_only
true
ghsa_published
2026-03-02T18:30:52Z
source_url
https://github.com/advisories/GHSA-5pmp-jpcf-pwx6
ghsa_updated
2026-03-02T18:30:53Z

Related Entities (2)

AFFECTS (1)

[Software]rust/tracing-check

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-5pmp-jpcf-pwx6 — Ninja Signal Threat Intelligence | Ninja Signal