{"id":"MAL-2026-3126","aliases":["GHSA-ffmx-5mf5-q3hc"],"title":"Malicious code in lsh (crates.io)","summary":"Malicious code in lsh (crates.io)","severity":"none","vendor":"lsh","product":"lsh","ecosystem":"rust","affected":["lsh"],"published":"2026-04-28","updated":"2026-07-18","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-3126","references":[{"url":"https://github.com/advisories/GHSA-ffmx-5mf5-q3hc"}],"tags":["osv","rust"],"ingestedAt":"2026-07-18T19:01:59.523Z","slug":"MAL-2026-3126","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ghsa-malware (8989a6e7b570a831dde23514a11fe5d8b44919c470e8532ec6103864146d0e8d)\n## Source: ossf-package-analysis (8cd6cecd3051e3998c5f96ec8dbe1bcfffc1ed7133d394a1779c8c1b0252c8c0)\nThe OpenSSF Package Analysis project identified 'lsh' @ 99.0.1 (crates.io) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n\n---\n\nCredit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a38ecee305c88a229e05893a0413264b62143ce2/osv/malicious/crates.io/lsh/MAL-2026-3126.json))\n\n## Source: ossf-package-analysis (8cd6cecd3051e3998c5f96ec8dbe1bcfffc1ed7133d394a1779c8c1b0252c8c0)\nThe OpenSSF Package Analysis project identified 'lsh' @ 99.0.1 (crates.io) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n\n\n## Affected packages\n\n- `lsh`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}