criticalVulnerability

GHSA-g38r-8gmr-ghrf

`mysten-metrics` included a build script that attempted to exfiltrate data from the build machine. The malicious crate had 1 version published on 2026-04-20 and had no evidence of actual usage. This crate had no dependencies on crates.io.

Properties

ghsa_id
GHSA-g38r-8gmr-ghrf
severity
critical
summary
`mysten-metrics` was removed from crates.io for malicious code
cve_id
GHSA-g38r-8gmr-ghrf
is_ghsa_only
true
ghsa_published
2026-05-04T21:43:56Z
source_url
https://github.com/advisories/GHSA-g38r-8gmr-ghrf
ghsa_updated
2026-05-04T21:43:58Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]rust/mysten-metrics

AFFECTS (1)

[Software]rust/mysten-metrics

HAS_WEAKNESS (1)

[Weakness]Embedded Malicious Code

Explore deeper with Ninja Signal's threat intelligence graph