{"id":"GHSA-vgr2-r5hm-f6gf","aliases":["RUSTSEC-2025-0151"],"url":"https://o3.security/vulnerability/GHSA-vgr2-r5hm-f6gf","summary":"`sha-rst` was removed from crates.io for malicious code","details":"This crate was used as a dependency by `finch_cli_rust` and `finch-rst` and contained a malware payload to exfiltrate credentials.\n\nThe malicious crate had 1 version published on 2025-12-08 and had been downloaded 22 times. Other than the other crates above that were part of the attack, no other crates depedended on this crate.\n\nThanks to Matthias Zepper of [NGI Sweden](https://ngisweden.scilifelab.se/) for reporting this to the crates.io team!","published":"2026-02-12T22:11:08Z","modified":"2026-02-13T07:26:25.950139Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"sha-rst","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0151.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-13T07:26:25.950139Z"}}