Junglewise Threat Intelligence

Rust exploration crate embedded malicious code

Severity: critical · Published 2026-07-10

Vendors: crates.io.

Executive brief

The 'exploration' package, a library previously available on the Rust package registry (crates.io), was found to contain malicious code. This code was designed to automatically download and run unauthorized software from a remote server when used. The package has been removed from the registry to prevent further risk to developers and their systems.

Technical details

The 'exploration' crate contained embedded malicious code (CWE-506) that attempted to download and execute an external payload from a remote site upon invocation of a specific method. The package was published to crates.io on 2026-06-02 and remained available for approximately one hour before being identified and removed. There are no known safe versions of this crate. Security researchers found no evidence of widespread usage before its removal. Developers who may have downloaded this crate should treat their environments as compromised.

Affected products

  • Rust crates.io exploration >= 0

Timeline

  • 2026-06-02: disclosed: Malicious crate published and removed within one hour.
  • 2026-07-10: advisory: GitHub Advisory published.

References

Related threats