criticalVulnerability

GHSA-6v2j-vr4h-f632

This attempts to typosquat the existing crate [`finch_cli`](https://crates.io/crates/finch_cli) to steal credentials from local files. The malicious crate had 1 version published on 2025-12-08 and had been downloaded 18 times. There were no crates depending on this crate on crates.io. Thanks to Matthias Zepper of [NGI Sweden](https://ngisweden.scilifelab.se/) for reporting this to the crates.io team!

Properties

ghsa_id
GHSA-6v2j-vr4h-f632
severity
critical
summary
`finch_cli_rust` was removed from crates.io for malicious code
cve_id
GHSA-6v2j-vr4h-f632
is_ghsa_only
true
ghsa_published
2026-02-12T22:10:47Z
source_url
https://github.com/advisories/GHSA-6v2j-vr4h-f632
ghsa_updated
2026-02-12T22:10:48Z

Related Entities (3)

AFFECTS (1)

[Software]rust/finch_cli_rust

HAS_WEAKNESS (1)

[Weakness]Embedded Malicious Code

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph