criticalVulnerability
GHSA-xhw7-jhmp-j62j
The `dnp3times` crate attempted to exfiltrate `.env` files to a server that was in turn impersonating the legitimate `timeapi.io` service. It was loosely trying to typosquat the `dnp3time` crate, but otherwise was the same attack as the recent `time_calibrator` and `time_calibrators` malware. The malicious crate had 1 version published on 2026-03-04 approximately 6 hours before removal and had no evidence of actual downloads. There were no crates depending on this crate on crates.io.
Properties
- ghsa_id
- GHSA-xhw7-jhmp-j62j
- severity
- critical
- summary
- `dnp3times` was removed from crates.io due to malicious code
- cve_id
- GHSA-xhw7-jhmp-j62j
- is_ghsa_only
- true
- ghsa_published
- 2026-03-05T00:43:57Z
- source_url
- https://github.com/advisories/GHSA-xhw7-jhmp-j62j
- ghsa_updated
- 2026-03-05T00:43:57Z
Related Entities (2)
AFFECTS (1)
→[Software]rust/dnp3times
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph