{"id":"GHSA-6v2j-vr4h-f632","summary":"`finch_cli_rust` was removed from crates.io for malicious code","details":"This attempts to typosquat the existing crate [`finch_cli`](https://crates.io/crates/finch_cli) to steal credentials from local files.\n\nThe malicious crate had 1 version published on 2025-12-08 and had been downloaded 18 times. There were no crates depending on this crate on crates.io.\n\nThanks to Matthias Zepper of [NGI Sweden](https://ngisweden.scilifelab.se/) for reporting this to the crates.io team!","aliases":["RUSTSEC-2025-0152"],"modified":"2026-02-13T04:56:33.752059Z","published":"2026-02-12T22:10:47Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-02-12T22:10:47Z","nvd_published_at":null,"cwe_ids":["CWE-506"]},"references":[{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0152.html"}],"affected":[{"package":{"name":"finch_cli_rust","ecosystem":"crates.io","purl":"pkg:cargo/finch_cli_rust"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-6v2j-vr4h-f632/GHSA-6v2j-vr4h-f632.json"}}],"schema_version":"1.9.0"}