VDB
GCVE-110-OSM-2026-8457
GCVE-110-OSM-2026-8457
Advisory PublishedCVSS 8.8/10
`rands` was removed from crates.io for malicious code
Details: This crate attempted to typosquat the `rand` crate, and would link in a malware
payload on macOS and Linux hosts when built.
This advisory is to retrospectively document this attempted attack. The version
information and download records of the malicious crate are no longer
available. The related malicious crates have been yanked, and the malicious
account has been banned.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | rands | all (affected) | — |
Browse GCVE Records
77,606 records in the GCVE database · Updated August 8, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.