RUSTSEC-2026-0280

    Dashboard / Vulnerabilities / RUSTSEC-2026-0280

    RUSTSEC-2026-0280

    Published: 7 Sept 2026Last Modified: 7 Sept 2026

    Summary: `greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code

    Details: A new version of the `greentic-setup-dev` crate was published with a variant of the PolinRider malware included that would fire when a project depending on `greentic-setup-dev` was opened in Visual Studio Code. One malicious version was published on 2026-09-06, approximately 27 hours before removal. This crate has no dependencies on crates.io. We have no evidence that this crate version was downloaded by any actual users, but Greentic users should check their systems nonetheless. Thanks to the Research Team at Nextron Systems GmbH for the report.

    Affected packages

    Package

    Name: greentic-setup-dev

    Purl: pkg:cargo/greentic-setup-dev

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 1.3.34027618345
    Fixed -1.3.34027618346-0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2026-0280 | CVE-DB