MAL-2026-14339

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/crates.io/proc_macro_en/MAL-2026-14339.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-14339
Published
2026-08-20T00:00:00Z
Modified
2026-08-20T23:34:38.264779211Z
Summary
Malicious code in proc_macro_en (crates.io)
Details

proc-macro-en is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign.

References
Credits

Affected packages

crates.io / proc-macro-en

Package

Name
proc-macro-en
View open source insights on deps.dev
Purl
pkg:cargo/proc-macro-en

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/crates.io/proc_macro_en/MAL-2026-14339.json"