PT-2025-54920 · Crates.Io · Rands

Published

2025-02-10

·

Updated

2025-02-10

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This crate attempted to typosquat the rand crate, and would link in a malware payload on macOS and Linux hosts when built.
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

RUSTSEC-2025-0155

Affected Products

Rands