VDB

GCVE-110-OSM-2026-8457

GCVE-110-OSM-2026-8457
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 18, 2026
`rands` was removed from crates.io for malicious code Details: This crate attempted to typosquat the `rand` crate, and would link in a malware payload on macOS and Linux hosts when built. This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownrandsall (affected)

References

vendor

Browse GCVE Records

77,606 records in the GCVE database · Updated August 8, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›