RUSTSEC-2026-0265

Source
https://rustsec.org/advisories/RUSTSEC-2026-0265
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0265.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0265
Published
2026-08-20T12:00:00Z
Modified
2026-08-21T06:30:03.173607233Z
Summary
`proc-macro1` was removed from crates.io due to malicious code
Details

It was reported proc-macro1 contained a build script that would download a malicious payload.

This crate had two versions, both published on 2026-08-20. The crate was removed from crates.io and related user accounts were locked.

This crate was used as part of a malware campaign targeted at users of arrayref, which was downloaded 2,285 times before being removed; see the arrayref advisory for more detail.

Thanks to the Research Team at Nextron Systems GmbH for reporting this to the Rust security response working group, and thanks to Emily Albini for coordinating with the crates.io and infra-admin teams.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / proc-macro1

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0

Ecosystem specific

{
    "affects": {
        "arch": [],
        "os": [],
        "functions": []
    },
    "affected_functions": null
}

Database specific

informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0265.json"
categories
[
    "malicious"
]
cvss
null