criticalVulnerability

GHSA-xhw7-jhmp-j62j

The `dnp3times` crate attempted to exfiltrate `.env` files to a server that was in turn impersonating the legitimate `timeapi.io` service. It was loosely trying to typosquat the `dnp3time` crate, but otherwise was the same attack as the recent `time_calibrator` and `time_calibrators` malware. The malicious crate had 1 version published on 2026-03-04 approximately 6 hours before removal and had no evidence of actual downloads. There were no crates depending on this crate on crates.io.

Properties

ghsa_id
GHSA-xhw7-jhmp-j62j
severity
critical
summary
`dnp3times` was removed from crates.io due to malicious code
cve_id
GHSA-xhw7-jhmp-j62j
is_ghsa_only
true
ghsa_published
2026-03-05T00:43:57Z
source_url
https://github.com/advisories/GHSA-xhw7-jhmp-j62j
ghsa_updated
2026-03-05T00:43:57Z

Related Entities (2)

AFFECTS (1)

[Software]rust/dnp3times

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph