{"id":"GHSA-xhw7-jhmp-j62j","aliases":["RUSTSEC-2026-0032"],"url":"https://o3.security/vulnerability/GHSA-xhw7-jhmp-j62j","summary":"`dnp3times` was removed from crates.io due to malicious code","details":"The `dnp3times` crate attempted to exfiltrate `.env` files to a server that was in turn impersonating the legitimate `timeapi.io` service. It was loosely trying to typosquat the `dnp3time` crate, but otherwise was the same attack as the recent `time_calibrator` and `time_calibrators` malware.\n\nThe malicious crate had 1 version published on 2026-03-04 approximately 6 hours before removal and had no evidence of actual downloads. There were no crates depending on this crate on crates.io.","published":"2026-03-05T00:43:57Z","modified":"2026-03-05T06:11:18.700257Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"dnp3times","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0032.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-05T06:11:18.700257Z"}}