Skip to content

`sha-rst` was removed from crates.io for malicious code

Critical severity GitHub Reviewed Published Feb 12, 2026 to the GitHub Advisory Database • Updated Feb 12, 2026

Package

cargo sha-rst (Rust)

Affected versions

>= 0

Patched versions

None

Description

This crate was used as a dependency by finch_cli_rust and finch-rst and contained a malware payload to exfiltrate credentials.

The malicious crate had 1 version published on 2025-12-08 and had been downloaded 22 times. Other than the other crates above that were part of the attack, no other crates depedended on this crate.

Thanks to Matthias Zepper of NGI Sweden for reporting this to the crates.io team!

References

Published to the GitHub Advisory Database Feb 12, 2026
Reviewed Feb 12, 2026
Last updated Feb 12, 2026

Severity

Critical

EPSS score

Weaknesses

Embedded Malicious Code

The product contains code that appears to be malicious in nature. Learn more on MITRE.

CVE ID

No known CVE

GHSA ID

GHSA-vgr2-r5hm-f6gf

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.