Skip to content

`sui-execution-cut` was removed from crates.io for malicious code

Critical severity GitHub Reviewed Published May 4, 2026 to the GitHub Advisory Database • Updated May 4, 2026

Package

cargo sui-execution-cut (Rust)

Affected versions

>= 0

Patched versions

None

Description

sui-execution-cut included a build script that attempted to exfiltrate data from the build machine.

The malicious crate had 1 version published on 2026-04-20 and had no evidence of actual usage. This crate had no dependencies on crates.io.

References

Published to the GitHub Advisory Database May 4, 2026
Reviewed May 4, 2026
Last updated May 4, 2026

Severity

Critical

EPSS score

Weaknesses

Embedded Malicious Code

The product contains code that appears to be malicious in nature. Learn more on MITRE.

CVE ID

No known CVE

GHSA ID

GHSA-qprh-m6p3-hwxc

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.