GHSA-99j7-fhr2-xfj4Critical▾ Midnight`exploration` was removed from crates.io for malicious code
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A method within the exploration crate attempted to download and execute a payload from a remote site.
The malicious crate had 1 version published on 2026-06-02, approximately 1 hour before removal, and had no evidence of actual usage. This crate had no dependencies on crates.io.
Rustsec to Kirill Boychenko from the Socket Threat Research Team for reporting this crate.
exploration >= 0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
RUSTSEC-2026-0155None`exploration` was removed from crates.io for malicious code
CVE-2024-3094Critical· 10.0Malicious backdoor in xz/liblzma (supply-chain compromise)
CVE-2026-74232Critical· 9.8Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.…
CVE-2026-67595High· 8.1VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
CVE-2025-30066High· 8.6tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs
CVE-2025-59144High· 8.8debug is a JavaScript debugging utility