PT-2025-54920 · Crates.Io · Rands
Published
2025-02-10
·
Updated
2025-02-10
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This crate attempted to typosquat the
rand crate, and would link in a malware
payload on macOS and Linux hosts when built.This advisory is to retrospectively document this attempted attack. The version
information and download records of the malicious crate are no longer
available. The related malicious crates have been yanked, and the malicious
account has been banned.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rands