---
id: MAL-2026-6959
title: Malicious code in proton_pfff (crates.io)
summary: Malicious code in proton_pfff (crates.io)
severity: none
vendor: proton-pfff
product: proton-pfff
ecosystem: rust
affected:
  - proton-pfff
published: '2026-07-08'
updated: '2026-07-08'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-6959'
tags:
  - osv
  - rust
ingestedAt: '2026-07-09T18:56:37.349Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: ossf-package-analysis (0aa190f5fe08b29ab6f7230c099bdc2a201b7d5212f434f9e44b2be1feba5de1)
The OpenSSF Package Analysis project identified 'proton-pfff' @ 99.99.5 (crates.io) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

- The package executes one or more commands associated with malicious behavior.


## Affected packages

- `proton-pfff`

## Remediation

Refer to the advisory for the patched release.
