VDB
GCVE-110-OSM-2026-8486
GCVE-110-OSM-2026-8486
Advisory PublishedCVSS 8.8/10
`envlogger` was removed from crates.io for malicious code
Details: This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
reporting this to the crates.io team!
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | envlogger | all (affected) | — |
Browse GCVE Records
75,792 records in the GCVE database · Updated August 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.