Advisory Database
  • Advisories
  • Dependency Scanning
  1. cargo
  2. ›
  3. finch_cli_rust
  4. ›
  5. GHSA-6v2j-vr4h-f632

GHSA-6v2j-vr4h-f632: `finch_cli_rust` was removed from crates.io for malicious code

February 12, 2026

This attempts to typosquat the existing crate finch_cli to steal credentials from local files.

The malicious crate had 1 version published on 2025-12-08 and had been downloaded 18 times. There were no crates depending on this crate on crates.io.

Thanks to Matthias Zepper of NGI Sweden for reporting this to the crates.io team!

References

  • github.com/advisories/GHSA-6v2j-vr4h-f632
  • rustsec.org/advisories/RUSTSEC-2025-0152.html

Code Behaviors & Features

Detect and mitigate GHSA-6v2j-vr4h-f632 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions

Solution

Unfortunately, there is no solution available yet.

Weakness

  • CWE-506: Embedded Malicious Code

Source file

cargo/finch_cli_rust/GHSA-6v2j-vr4h-f632.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 25 Mar 2026 00:17:04 +0000.