VDB

GCVE-110-OSM-2026-8489

GCVE-110-OSM-2026-8489
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 17, 2026
Dependency-confusion/typosquat crate published by removed crates.io account alonebeast002 as part of a 10+ crate campaign (2026-04-27 to 2026-04-30) targeting Crate package names. All versions published at 99.x to win Cargo version resolution. Removed by crates.io admins. Important note! There is a new Crates.io user who published a new lsh package on June 11, 2026. This user appears to be totally legitimate. We are not naming their account here to avoid unfairly flagging them as malicious. This is the downside of the Crates team silently removing the lsh package from the registry; now this legitimate user is at risk of being flagged as malicious. Malicious code in build.rs (executes at build time). Collects system and user data on the victim and exfiltrates to Telegram channel controlled by the attacker.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownlsh99.0.0, 99.0.1, 99.0.2, 99.0.6, 99.1.0 (affected)

References

vendor

Browse GCVE Records

75,827 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›