RUSTSEC-2026-0281

    Dashboard / Vulnerabilities / RUSTSEC-2026-0281

    RUSTSEC-2026-0281

    Published: 7 Sept 2026Last Modified: 7 Sept 2026

    Summary: `greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code

    Details: A new version of the `greentic-setup` crate was published with a variant of the PolinRider malware included that would fire when a project depending on `greentic-setup` was opened in Visual Studio Code. One malicious version was published on 2026-09-06, approximately 27 hours before removal. This crate is depended on by four other crates in the Greentic ecosystem, namely `greentic-start`, `greentic-start-dev`, `greentic-operator`, and `greentic-operator-dev`. We have no evidence that this crate version was downloaded by any actual users, but Greentic users should check their systems nonetheless. Thanks to the Research Team at Nextron Systems GmbH for the report.

    Affected packages

    Package

    Name: greentic-setup

    Purl: pkg:cargo/greentic-setup

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 1.3.1-dev.34027618345
    Fixed -1.3.1-dev.34027618345.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2026-0281 | CVE-DB