{"id":"MAL-2026-14337","summary":"Malicious code in internment (crates.io)","details":"internment 0.8.7 was published to crates.io from the same maintainer account (droundy) as the trojanized arrayref and append-only-vec releases, which appears to be compromised. The release adds a dependency on an attacker-controlled crate whose build script downloads and executes an architecture-specific remote binary at build time from https://23.254.165.112:9089/, passing 23.254.165.112:443 as a command-and-control address. Part of a coordinated crates.io campaign on 2026-08-20. The malicious release has been removed from crates.io; earlier internment releases are unaffected.","modified":"2026-08-21T00:01:42.187838427Z","published":"2026-08-20T00:00:00Z","references":[{"type":"REPORT","url":"https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/"},{"type":"WEB","url":"https://github.com/rustsec/advisory-db/issues/3161"}],"affected":[{"package":{"name":"internment","ecosystem":"crates.io","purl":"pkg:cargo/internment"},"versions":["0.8.7"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/crates.io/internment/MAL-2026-14337.json"}}],"schema_version":"1.9.0","credits":[{"name":"SafeDep","contact":["https://safedep.io"],"type":"FINDER"},{"name":"jhobern","contact":["https://github.com/jhobern"],"type":"REPORTER"}]}