{"id":"MAL-2026-6959","title":"Malicious code in proton_pfff (crates.io)","summary":"Malicious code in proton_pfff (crates.io)","severity":"none","vendor":"proton-pfff","product":"proton-pfff","ecosystem":"rust","affected":["proton-pfff"],"published":"2026-07-08","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-6959","tags":["osv","rust"],"ingestedAt":"2026-07-09T18:56:37.349Z","slug":"MAL-2026-6959","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (0aa190f5fe08b29ab6f7230c099bdc2a201b7d5212f434f9e44b2be1feba5de1)\nThe OpenSSF Package Analysis project identified 'proton-pfff' @ 99.99.5 (crates.io) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n\n\n## Affected packages\n\n- `proton-pfff`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}