PT-2026-95056 · Crates.Io · Greentic-Setup

Publicado

2026-09-07

·

Atualizado

2026-09-07

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
A new version of the greentic-setup crate was published with a variant of the PolinRider malware included that would fire when a project depending on greentic-setup was opened in Visual Studio Code.
One malicious version was published on 2026-09-06, approximately 27 hours before removal. This crate is depended on by four other crates in the Greentic ecosystem, namely greentic-start, greentic-start-dev, greentic-operator, and greentic-operator-dev. We have no evidence that this crate version was downloaded by any actual users, but Greentic users should check their systems nonetheless.
Thanks to the Research Team at Nextron Systems GmbH for the report.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

RUSTSEC-2026-0281

Produtos afetados

Greentic-Setup