{"id":"RUSTSEC-2026-0281","title":"`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code","summary":"`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code","severity":"none","vendor":"greentic-setup","product":"greentic-setup","ecosystem":"rust","affected":["greentic-setup >= 1.3.1-dev.34027618345, < 1.3.1-dev.34027618345.0"],"patched":["greentic-setup 1.3.1-dev.34027618345.0"],"published":"2026-09-07","updated":"2026-09-07","sourceUpdated":"2026-09-07T18:23:30.834474167Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0281","references":[{"url":"https://crates.io/crates/greentic-setup"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0281.html"}],"tags":["osv","rust"],"ingestedAt":"2026-09-07T19:35:15.031Z","slug":"RUSTSEC-2026-0281","body":"## Overview\n\nA new version of the `greentic-setup` crate was published with a variant\nof the PolinRider malware included that would fire when a project\ndepending on `greentic-setup` was opened in Visual Studio Code.\n\nOne malicious version was published on 2026-09-06, approximately 27 hours\nbefore removal. This crate is depended on by four other crates in the\nGreentic ecosystem, namely `greentic-start`, `greentic-start-dev`,\n`greentic-operator`, and `greentic-operator-dev`. We have no evidence that this\ncrate version was downloaded by any actual users, but Greentic users should\ncheck their systems nonetheless.\n\nThanks to the Research Team at Nextron Systems GmbH for the report.\n\n## Affected packages\n\n- `greentic-setup >= 1.3.1-dev.34027618345, < 1.3.1-dev.34027618345.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `greentic-setup 1.3.1-dev.34027618345.0`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}