RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2025-0157

statsrelay-protobuf was removed from crates.io for malicious code

Reported
Issued
Package
statsrelay-protobuf
Type
Vulnerability
Categories
Patched
no patched versions

Description

statsrelay-protobuf was part of a campaign that attempted to exfiltrate environmental data from the host.

The malicious crate had 1 version published in August 2025, and had no evidence of actual usage. This crate had no dependencies on crates.io.

Advisory available under CC0-1.0 license.