criticalVulnerability
GHSA-mh23-rw7f-v5pq
The `time-sync` crate attempted to exfiltrate `.env` files to a server that was in turn impersonating the legitimate `timeapi.io` service. This the same attack that we've seen three times in the last few days. The malicious crate had 1 version published on 2026-03-04 approximately 50 minutes before removal and had no evidence of actual downloads. There were no crates depending on this crate on crates.io.
Properties
- ghsa_id
- GHSA-mh23-rw7f-v5pq
- severity
- critical
- summary
- `time-sync` was removed from crates.io due to malicious code
- cve_id
- GHSA-mh23-rw7f-v5pq
- is_ghsa_only
- true
- ghsa_published
- 2026-03-05T21:15:45Z
- source_url
- https://github.com/advisories/GHSA-mh23-rw7f-v5pq
- ghsa_updated
- 2026-03-05T21:15:45Z
Related Entities (2)
AFFECTS (1)
→[Software]rust/time-sync
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph