Advisory Database
  • Advisories
  • Dependency Scanning
  1. cargo
  2. ›
  3. polymarket-client-sdks
  4. ›
  5. GHSA-p5vf-5754-x7p3

GHSA-p5vf-5754-x7p3: `polymarket-client-sdks` was removed from crates.io for malicious code

February 13, 2026

It appeared to be typosquatting existing crate polymarket-client-sdk (sdks vs sdk) and attempting to steal credentials from local files.

The malicious crate had 1 version published on 2026-02-09 and had been downloaded only 33 times. There were no crates depending on this crate on crates.io.

Thanks to Roland Peelen for finding and reporting this to the crates.io team!

References

  • github.com/advisories/GHSA-p5vf-5754-x7p3
  • rustsec.org/advisories/RUSTSEC-2026-0011.html

Code Behaviors & Features

Detect and mitigate GHSA-p5vf-5754-x7p3 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions

Solution

Unfortunately, there is no solution available yet.

Weakness

  • CWE-506: Embedded Malicious Code

Source file

cargo/polymarket-client-sdks/GHSA-p5vf-5754-x7p3.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 25 Mar 2026 00:17:11 +0000.