MAL-2026-14338

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/crates.io/proc_macro1/MAL-2026-14338.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-14338
Published
2026-08-20T00:00:00Z
Modified
2026-08-21T00:30:10Z
Summary
Malicious code in proc_macro1 (crates.io)
Details

proc-macro1 is a typosquat of proc-macro2 published to crates.io by the account 'dtolney', impersonating David Tolnay (dtolnay). Its metadata forges authors 'David Tolnay rchaitm@gmail.com' and points repository at a nonexistent github.com/dtolnay/proc-macro1. The library source is a copy of proc-macro2 so dependent builds succeed, but build.rs reconstructs a base64-encoded URL and downloads an architecture-specific remote binary from https://23.254.165.112:9089/ over TLS with certificate validation disabled (a custom verifier that accepts any certificate), then executes it detached, passing 23.254.165.112:443 as argv[1] (command and control). On Unix it writes and runs /tmp/rust-setup; on Windows it writes %TEMP%\rust-setup.ps1 and launches it via a %TEMP%\rust-setup-launch.vbs launcher under wscript.exe. The download and execution run unconditionally on every build on a supported platform. This crate was the payload carrier pulled in by the trojanized arrayref 0.3.10 release. All versions have been removed from crates.io.

Database specific
{
    "iocs": {
        "files": [
            {
                "note": "Unix second-stage binary, executed with 23.254.165.112:443 as argv[1]",
                "paths": [
                    "/tmp/rust-setup"
                ],
                "source": "DROPPED"
            },
            {
                "note": "Windows PowerShell second-stage",
                "paths": [
                    "%TEMP%\\rust-setup.ps1"
                ],
                "source": "DROPPED"
            },
            {
                "note": "Windows VBScript launcher for the PowerShell stage",
                "paths": [
                    "%TEMP%\\rust-setup-launch.vbs"
                ],
                "source": "DROPPED"
            }
        ],
        "ips": [
            "23.254.165.112"
        ],
        "urls": [
            "https://23.254.165.112:9089/rust-crate_0.1.0",
            "https://23.254.165.112:9089/rust-crate_0.2.0",
            "https://23.254.165.112:9089/rust-crate_0.3.0",
            "https://23.254.165.112:9089/rust-crate_0.4.0"
        ]
    }
}
References
Credits

Affected packages

crates.io / proc-macro1

Package

Name
proc-macro1
View open source insights on deps.dev
Purl
pkg:cargo/proc-macro1

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/crates.io/proc_macro1/MAL-2026-14338.json"