VDB
GCVE-110-OSM-2026-8489
GCVE-110-OSM-2026-8489
Advisory PublishedCVSS 8.8/10
Dependency-confusion/typosquat crate published by removed crates.io account alonebeast002 as part of a 10+ crate campaign (2026-04-27 to 2026-04-30) targeting Crate package names. All versions published at 99.x to win Cargo version resolution. Removed by crates.io admins.
Important note! There is a new Crates.io user who published a new lsh package on June 11, 2026. This user appears to be totally legitimate. We are not naming their account here to avoid unfairly flagging them as malicious. This is the downside of the Crates team silently removing the lsh package from the registry; now this legitimate user is at risk of being flagged as malicious.
Malicious code in build.rs (executes at build time). Collects system and user data on the victim and exfiltrates to Telegram channel controlled by the attacker.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | lsh | 99.0.0, 99.0.1, 99.0.2, 99.0.6, 99.1.0 (affected) | — |
Browse GCVE Records
75,827 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.