{"id":"GHSA-g38r-8gmr-ghrf","aliases":["RUSTSEC-2026-0107"],"url":"https://o3.security/vulnerability/GHSA-g38r-8gmr-ghrf","summary":"`mysten-metrics` was removed from crates.io for malicious code","details":"`mysten-metrics` included a build script that attempted to exfiltrate data from the build machine.\n\nThe malicious crate had 1 version published on 2026-04-20 and had no evidence of actual usage. This crate had no dependencies on crates.io.","published":"2026-05-04T21:43:56Z","modified":"2026-05-06T06:56:26.201706969Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"mysten-metrics","fixedVersion":null}],"fix":null,"references":[{"type":"PACKAGE","url":"https://github.com/MystenLabs/sui"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0107.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-06T06:56:26.201706969Z"}}