---
id: RUSTSEC-2026-0281
title: >-
  `greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to
  containing malicious code
summary: >-
  `greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to
  containing malicious code
severity: none
vendor: greentic-setup
product: greentic-setup
ecosystem: rust
affected:
  - 'greentic-setup >= 1.3.1-dev.34027618345, < 1.3.1-dev.34027618345.0'
patched:
  - greentic-setup 1.3.1-dev.34027618345.0
published: '2026-09-07'
updated: '2026-09-07'
sourceUpdated: '2026-09-07T18:23:30.834474167Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0281'
references:
  - url: 'https://crates.io/crates/greentic-setup'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0281.html'
tags:
  - osv
  - rust
ingestedAt: '2026-09-07T19:35:15.031Z'
---

## Overview

A new version of the `greentic-setup` crate was published with a variant
of the PolinRider malware included that would fire when a project
depending on `greentic-setup` was opened in Visual Studio Code.

One malicious version was published on 2026-09-06, approximately 27 hours
before removal. This crate is depended on by four other crates in the
Greentic ecosystem, namely `greentic-start`, `greentic-start-dev`,
`greentic-operator`, and `greentic-operator-dev`. We have no evidence that this
crate version was downloaded by any actual users, but Greentic users should
check their systems nonetheless.

Thanks to the Research Team at Nextron Systems GmbH for the report.

## Affected packages

- `greentic-setup >= 1.3.1-dev.34027618345, < 1.3.1-dev.34027618345.0`

## Remediation

Upgrade to a patched release:

- `greentic-setup 1.3.1-dev.34027618345.0`
