PT-2026-95055 · Crates.Io · Greentic-Setup-Dev
Published
2026-09-07
·
Updated
2026-09-07
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
A new version of the
greentic-setup-dev crate was published with a variant of
the PolinRider malware included that would fire when a project depending on
greentic-setup-dev was opened in Visual Studio Code.One malicious version was published on 2026-09-06, approximately 27 hours
before removal. This crate has no dependencies on crates.io. We have no
evidence that this crate version was downloaded by any actual users, but
Greentic users should check their systems nonetheless.
Thanks to the Research Team at Nextron Systems GmbH for the report.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Greentic-Setup-Dev