criticalVulnerability

GHSA-vgr2-r5hm-f6gf

This crate was used as a dependency by `finch_cli_rust` and `finch-rst` and contained a malware payload to exfiltrate credentials. The malicious crate had 1 version published on 2025-12-08 and had been downloaded 22 times. Other than the other crates above that were part of the attack, no other crates depedended on this crate. Thanks to Matthias Zepper of [NGI Sweden](https://ngisweden.scilifelab.se/) for reporting this to the crates.io team!

Properties

ghsa_id
GHSA-vgr2-r5hm-f6gf
severity
critical
summary
`sha-rst` was removed from crates.io for malicious code
cve_id
GHSA-vgr2-r5hm-f6gf
is_ghsa_only
true
ghsa_published
2026-02-12T22:11:08Z
source_url
https://github.com/advisories/GHSA-vgr2-r5hm-f6gf
ghsa_updated
2026-02-12T22:11:09Z

Related Entities (3)

AFFECTS (1)

[Software]rust/sha-rst

HAS_WEAKNESS (1)

[Weakness]Embedded Malicious Code

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-vgr2-r5hm-f6gf — Ninja Signal Threat Intelligence | Ninja Signal