diff --git a/crates/finch-rust/RUSTSEC-0000-0000.md b/crates/finch-rust/RUSTSEC-0000-0000.md new file mode 100644 index 000000000..66c151d6b --- /dev/null +++ b/crates/finch-rust/RUSTSEC-0000-0000.md @@ -0,0 +1,15 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "finch-rust" +date = "2025-12-05" +url = "https://blog.rust-lang.org/2025/12/05/crates.io-malicious-crates-finch-rust-and-sha-rust/" +references = ["https://socket.dev/blog/malicious-crate-mimicking-finch-exfiltrates-credentials"] + +[versions] +patched = [] +``` + +# `finch-rust` was removed from crates.io for malicious code + +It depended on the `sha-rust` crate, which appeared to be attempting to steal credentials from local files. diff --git a/crates/sha-rust/RUSTSEC-0000-0000.md b/crates/sha-rust/RUSTSEC-0000-0000.md new file mode 100644 index 000000000..b1f5920f6 --- /dev/null +++ b/crates/sha-rust/RUSTSEC-0000-0000.md @@ -0,0 +1,15 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "sha-rust" +date = "2025-12-05" +url = "https://blog.rust-lang.org/2025/12/05/crates.io-malicious-crates-finch-rust-and-sha-rust/" +references = ["https://socket.dev/blog/malicious-crate-mimicking-finch-exfiltrates-credentials"] + +[versions] +patched = [] +``` + +# `sha-rust` was removed from crates.io for malicious code + +It appeared to be attempting to steal credentials from local files.