{"id":"RUSTSEC-2026-0263","summary":"`tinymember` was removed from crates.io due to affiliation with malicious code","details":"While `tinymember` did not directly contain malicious code, it was owned by the\nsame user as `arone` and `aronenao`, which contained suspicious build scripts.\n\nThis crate had 2 versions published on 2026-08-18 that had a total of 27 downloads.\nThere were no crates depending on this crate on crates.io. The crate was removed\nfrom crates.io and the user account was locked.","modified":"2026-08-20T16:02:07.643054977Z","published":"2026-08-20T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/tinymember"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0263.html"},{"type":"WEB","url":"https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"}],"affected":[{"package":{"name":"tinymember","ecosystem":"crates.io","purl":"pkg:cargo/tinymember"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"}]}],"ecosystem_specific":{"affects":{"functions":[],"arch":[],"os":[]},"affected_functions":null},"database_specific":{"cvss":null,"informational":null,"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0263.json","categories":[]}}],"schema_version":"1.9.0"}