RUSTSEC-2026-0030

Source
https://rustsec.org/advisories/RUSTSEC-2026-0030
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0030.json
JSON Data
https://api.test.osv.dev/v1/vulns/RUSTSEC-2026-0030
Published
2026-03-03T12:00:00Z
Modified
2026-03-03T18:43:19.338982Z
Summary
`time_calibrator` was removed from crates.io due to malicious code
Details

It was reported time_calibrator contained malicious code, that would try to upload .env files to a server.

The malicious crate had only 1 version published at 2026-02-28 and no evidence of actual usage. The crate was removed from crates.io and the user account was locked. There were no crates depending on this crate on crates.io.

Thanks to Gabriel Silva for finding and reporting this to the Rust security response working group, and thanks to Emily Albini for co-ordinating with the crates.io and infra-admin teams.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / time_calibrator

Package

Name
time_calibrator
View open source insights on deps.dev
Purl
pkg:cargo/time_calibrator

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "os": [],
        "arch": [],
        "functions": []
    }
}

Database specific

cvss
null
categories
[]
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0030.json"