RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0280

greentic-setup-dev 1.3.34027618345 was removed from crates.io due to containing malicious code

Reported
Issued
Package
greentic-setup-dev (crates.io)
Type
Vulnerability
Categories
Patched
no patched versions
Unaffected
  • <1.3.34027618345
  • >1.3.34027618345

Description

A new version of the greentic-setup-dev crate was published with a variant of the PolinRider malware included that would fire when a project depending on greentic-setup-dev was opened in Visual Studio Code.

One malicious version was published on 2026-09-06, approximately 27 hours before removal. This crate has no dependencies on crates.io. We have no evidence that this crate version was downloaded by any actual users, but Greentic users should check their systems nonetheless.

Thanks to the Research Team at Nextron Systems GmbH for the report.

Advisory available under CC0-1.0 license.