RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2025-0159

sophosfirewall-python was removed from crates.io for malicious code

Reported
Issued
Package
sophosfirewall-python
Type
Vulnerability
Categories
Patched
no patched versions

Description

sophosfirewall-python was part of a campaign that attempted to exfiltrate environmental data from the host.

The malicious crate had 6 versions published in February 2025, and had no evidence of actual usage. This crate had no dependencies on crates.io.

Advisory available under CC0-1.0 license.