{"id":"MAL-2026-14334","summary":"Malicious code in arone (crates.io)","details":"arone is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign.","modified":"2026-08-21T00:01:43.059086512Z","published":"2026-08-20T00:00:00Z","references":[{"type":"REPORT","url":"https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/"},{"type":"WEB","url":"https://github.com/rustsec/advisory-db/issues/3161"}],"affected":[{"package":{"name":"arone","ecosystem":"crates.io","purl":"pkg:cargo/arone"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/crates.io/arone/MAL-2026-14334.json"}}],"schema_version":"1.9.0","credits":[{"name":"SafeDep","contact":["https://safedep.io"],"type":"FINDER"},{"name":"jhobern","contact":["https://github.com/jhobern"],"type":"REPORTER"}]}