criticalVulnerability
GHSA-xp79-9mxw-878j
This attempts to typosquat the existing crate [`finch`](https://crates.io/crates/finch) to steal credentials from local files. The malicious crate had 1 version published on 2025-12-08 and had been downloaded 21 times. There were no crates depending on this crate on crates.io. Thanks to Matthias Zepper of [NGI Sweden](https://ngisweden.scilifelab.se/) for reporting this to the crates.io team!
Properties
- ghsa_id
- GHSA-xp79-9mxw-878j
- severity
- critical
- summary
- `finch-rst` was removed from crates.io for malicious code
- cve_id
- GHSA-xp79-9mxw-878j
- is_ghsa_only
- true
- ghsa_published
- 2026-02-12T22:10:23Z
- source_url
- https://github.com/advisories/GHSA-xp79-9mxw-878j
- ghsa_updated
- 2026-02-12T22:10:27Z
Related Entities (3)
AFFECTS (1)
→[Software]rust/finch-rst
HAS_WEAKNESS (1)
→[Weakness]Embedded Malicious Code
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph