{"id":"GHSA-382q-fpqh-29f7","aliases":["RUSTSEC-2026-0010"],"url":"https://o3.security/vulnerability/GHSA-382q-fpqh-29f7","summary":"`polymarket-clients-sdk` was removed from crates.io for malicious code","details":"It appeared to be typosquatting existing crate [`polymarket-client-sdk`](https://crates.io/crates/polymarket-client-sdk) (`clients` vs `client`) and attempting to steal credentials from local files.\n\nThe malicious crate had 6 versions published on 2026-02-05 and had been downloaded only 59 times. There were no crates depending on this crate on crates.io.\n\nPolymarket thanks [Socket.dev](https://socket.dev/) for detecting and reporting this to the crates.io team!","published":"2026-02-06T20:56:19Z","modified":"2026-02-23T07:26:19.505794Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"polymarket-clients-sdk","fixedVersion":null}],"fix":null,"references":[{"type":"PACKAGE","url":"https://github.com/Polymarket/rs-clob-client"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0010.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-23T07:26:19.505794Z"}}