File tree Expand file tree Collapse file tree 1 file changed +26
-0
lines changed
crates/polymarkets-client-sdk Expand file tree Collapse file tree 1 file changed +26
-0
lines changed Original file line number Diff line number Diff line change 1+ ``` toml
2+ [advisory ]
3+ id = " RUSTSEC-0000-0000"
4+ package = " polymarkets-client-sdk"
5+ date = " 2026-02-19"
6+ expect-deleted = true
7+
8+ [versions ]
9+ patched = []
10+ ```
11+
12+ # ` polymarkets-client-sdk ` was removed from crates.io for malicious code
13+
14+ It appeared to be typosquatting existing crate
15+ [ ` polymarket-client-sdk ` ] ( https://crates.io/crates/polymarket-client-sdk ) (` polymarkets ` vs
16+ ` polymarket ` ) and attempting to steal credentials from local files.
17+
18+ The malicious crate had 1 version published on 2026-02-19 an hour before removal and hadn't been
19+ downloaded. There were no crates depending on this crate on crates.io.
20+
21+ Thanks to Carol Nichols, who is thanking herself for spotting this in the docs.rs build queue and
22+ removing it quickly!
23+
24+ The crates.io team advises anyone developing with Polymarket to review dependencies carefully. We
25+ are investigating ways to mitigate this attacker who appears to be very motivated to steal
26+ Polymarket credentials.
You can’t perform that action at this time.
0 commit comments