RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2025-0160

custom-req-on-workers was removed from crates.io for malicious code

Reported
Issued
Package
custom-req-on-workers
Type
Vulnerability
Categories
Patched
no patched versions

Description

custom-req-on-workers was part of a campaign that attempted to exfiltrate environmental data from the host.

The malicious crate had 1 version published in January 2025, and had no evidence of actual usage. This crate had no dependencies on crates.io.

Advisory available under CC0-1.0 license.