VDB
Sign up
—

RUSTSEC-2026-0014

`rpc-check` was removed from crates.io for malicious code

Details

It was attempting to steal credentials from the `POLYMARKET_PRIVATE_KEY` environment variable.

The malicious crate had 3 versions published on 2026-02-15 and had been downloaded only 155 times. There were no crates depending on this crate on crates.io.

Thanks to Sisong Li for finding and reporting this to the crates.io team!

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/rpc-check
Introduced in: 0.0.0-0

No fixed version published yet for rpc-check. Pin to a known-safe version or switch to an alternative.

References