RUSTSEC-2026-0281
Dashboard / Vulnerabilities / RUSTSEC-2026-0281
RUSTSEC-2026-0281
Summary: `greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code
Details: A new version of the `greentic-setup` crate was published with a variant of the PolinRider malware included that would fire when a project depending on `greentic-setup` was opened in Visual Studio Code. One malicious version was published on 2026-09-06, approximately 27 hours before removal. This crate is depended on by four other crates in the Greentic ecosystem, namely `greentic-start`, `greentic-start-dev`, `greentic-operator`, and `greentic-operator-dev`. We have no evidence that this crate version was downloaded by any actual users, but Greentic users should check their systems nonetheless. Thanks to the Research Team at Nextron Systems GmbH for the report.
References: https://crates.io/crates/greentic-setup, https://rustsec.org/advisories/RUSTSEC-2026-0281.html
Affected packages
Package
Name: greentic-setup
Purl: pkg:cargo/greentic-setup
Affected ranges
Type: SEMVER
Events:
