VDB

GCVE-110-OSM-2026-8476

GCVE-110-OSM-2026-8476
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 18, 2026
`postgresderive` was removed from crates.io for malicious code Details: This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in `build.rs` to exfiltrate host information to the attacker. This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. Thanks to Louis Lang at [Phylum] (now [Veracode]) for reporting this malware campaign. [Phylum]: https://phylum.io/ [Veracode]: https://www.veracode.com/

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownpostgresderiveall (affected)

References

vendor

Browse GCVE Records

76,198 records in the GCVE database · Updated August 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›