{"id":"GHSA-mh23-rw7f-v5pq","aliases":["RUSTSEC-2026-0036"],"url":"https://o3.security/vulnerability/GHSA-mh23-rw7f-v5pq","summary":"`time-sync` was removed from crates.io due to malicious code","details":"The `time-sync` crate attempted to exfiltrate `.env` files to a server that was in turn impersonating the legitimate `timeapi.io` service. This the same attack that we've seen three times in the last few days.\n\nThe malicious crate had 1 version published on 2026-03-04 approximately 50 minutes before removal and had no evidence of actual downloads. There were no crates depending on this crate on crates.io.","published":"2026-03-05T21:15:45Z","modified":"2026-03-06T06:26:26.558032Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"time-sync","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0036.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-06T06:26:26.558032Z"}}