criticalVulnerability

GHSA-qprh-m6p3-hwxc

`sui-execution-cut` included a build script that attempted to exfiltrate data from the build machine. The malicious crate had 1 version published on 2026-04-20 and had no evidence of actual usage. This crate had no dependencies on crates.io.

Properties

ghsa_id
GHSA-qprh-m6p3-hwxc
severity
critical
summary
`sui-execution-cut` was removed from crates.io for malicious code
cve_id
GHSA-qprh-m6p3-hwxc
is_ghsa_only
true
ghsa_published
2026-05-04T21:42:55Z
source_url
https://github.com/advisories/GHSA-qprh-m6p3-hwxc
ghsa_updated
2026-05-04T21:42:58Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]rust/sui-execution-cut

AFFECTS (1)

[Software]rust/sui-execution-cut

HAS_WEAKNESS (1)

[Weakness]Embedded Malicious Code

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-qprh-m6p3-hwxc — Ninja Signal Threat Intelligence | Ninja Signal