{"id":"RUSTSEC-2026-0155","aliases":["GHSA-99j7-fhr2-xfj4"],"title":"`exploration` was removed from crates.io for malicious code","summary":"`exploration` was removed from crates.io for malicious code","severity":"none","vendor":"exploration","product":"exploration","ecosystem":"rust","affected":["exploration >= 0.0.0-0"],"published":"2026-06-02","updated":"2026-07-11","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0155","references":[{"url":"https://crates.io/crates/exploration"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0155.html"}],"tags":["osv","rust"],"ingestedAt":"2026-07-11T18:57:04.627Z","slug":"RUSTSEC-2026-0155","body":"## Overview\n\nA method within the `exploration` crate attempted to download and execute a\npayload from a remote site.\n\nThe malicious crate had 1 version published on 2026-06-02, approximately 1 hour\nbefore removal, and had no evidence of actual usage. This crate had no\ndependencies on crates.io.\n\nThanks to Kirill Boychenko from the [Socket Threat Research\nTeam](https://socket.dev/) for reporting this crate.\n\n## Affected packages\n\n- `exploration >= 0.0.0-0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}