File tree Expand file tree Collapse file tree 1 file changed +27
-0
lines changed
crates/polymarkets-rs-clob-client Expand file tree Collapse file tree 1 file changed +27
-0
lines changed Original file line number Diff line number Diff line change 1+ ``` toml
2+ [advisory ]
3+ id = " RUSTSEC-0000-0000"
4+ package = " polymarkets-rs-clob-client"
5+ date = " 2026-02-20"
6+ expect-deleted = true
7+
8+ [versions ]
9+ patched = []
10+ ```
11+
12+ # ` polymarkets-rs-clob-client ` was removed from crates.io for malicious code
13+
14+ This is part of an ongoing campaign to attempt to typosquat crates in the
15+ [ ` polymarket-client-sdk ` ] ( https://crates.io/crates/polymarket-client-sdk )
16+ ecosystem to exfiltrate user credentials.
17+
18+ The malicious crate had 1 version published on 2026-02-19 approximately 20
19+ hours before removal and had no evidence of actual downloads. There were no
20+ crates depending on this crate on crates.io.
21+
22+ Thanks to Adam Harvey at the Rust Foundation, who is awkwardly thanking himself
23+ in this instance.
24+
25+ The crates.io team advises anyone developing with Polymarket to review
26+ dependencies carefully. We are investigating ways to mitigate this attacker who
27+ appears to be very motivated to steal Polymarket credentials.
You can’t perform that action at this time.
0 commit comments