RUSTSEC-2026-0102
`microsoftsystem64` was removed from crates.io for malicious code
Details
`microsoftsystem64` installs a hardcoded SSH authorized_keys entry (persistence/backdoor) and scans for sensitive files (.env, credential-like JSON names, keyword-matching docs), reads their contents, base64-encodes where needed, and exfiltrates everything to a remote server via HTTP. It also packages and uploads Telegram Desktop tdata, indicating targeted credential/session/data harvesting.
The malicious crate had 9 versions published on 2026-04-09 that had a total of 6346 downloads. There were no crates depending on this crate on crates.io.
Thanks to [Socket.dev](https://socket.dev/) and [sitsh](https://sit.sh/) for detecting and reporting this to the crates.io team!
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0No fixed version published yet for microsoftsystem64. Pin to a known-safe version or switch to an alternative.