{"id":"GHSA-xp79-9mxw-878j","aliases":["RUSTSEC-2025-0150"],"url":"https://o3.security/vulnerability/GHSA-xp79-9mxw-878j","summary":"`finch-rst` was removed from crates.io for malicious code","details":"This attempts to typosquat the existing crate [`finch`](https://crates.io/crates/finch) to steal credentials from local files.\n\nThe malicious crate had 1 version published on 2025-12-08 and had been downloaded 21 times. There were no crates depending on this crate on crates.io.\n\nThanks to Matthias Zepper of [NGI Sweden](https://ngisweden.scilifelab.se/) for reporting this to the crates.io team!","published":"2026-02-12T22:10:23Z","modified":"2026-02-13T07:26:25.811129Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"finch-rst","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0150.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-13T07:26:25.811129Z"}}