criticalVulnerability

GHSA-mh23-rw7f-v5pq

The `time-sync` crate attempted to exfiltrate `.env` files to a server that was in turn impersonating the legitimate `timeapi.io` service. This the same attack that we've seen three times in the last few days. The malicious crate had 1 version published on 2026-03-04 approximately 50 minutes before removal and had no evidence of actual downloads. There were no crates depending on this crate on crates.io.

Properties

ghsa_id
GHSA-mh23-rw7f-v5pq
severity
critical
summary
`time-sync` was removed from crates.io due to malicious code
cve_id
GHSA-mh23-rw7f-v5pq
is_ghsa_only
true
ghsa_published
2026-03-05T21:15:45Z
source_url
https://github.com/advisories/GHSA-mh23-rw7f-v5pq
ghsa_updated
2026-03-05T21:15:45Z

Related Entities (2)

AFFECTS (1)

[Software]rust/time-sync

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph