{"id":"RUSTSEC-2026-0265","summary":"`proc-macro1` was removed from crates.io due to malicious code","details":"It was reported `proc-macro1` contained a build script that would download a\nmalicious payload.\n\nThis crate had two versions, both published on 2026-08-20. The crate was\nremoved from crates.io and related user accounts were locked.\n\nThis crate was used as part of a malware campaign targeted at users of\n`arrayref`, which was downloaded 2,285 times before being removed; see\n[the `arrayref` advisory][arrayref-advisory] for more detail.\n\nThanks to the Research Team at Nextron Systems GmbH for reporting this to the\nRust security response working group, and thanks to Emily Albini for coordinating\nwith the crates.io and infra-admin teams.\n\n[arrayref-advisory]: https://rustsec.org/advisories/RUSTSEC-2026-0260.html","modified":"2026-08-21T06:30:39.173394297Z","published":"2026-08-20T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/proc-macro1"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0265.html"},{"type":"WEB","url":"https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"}],"affected":[{"package":{"name":"proc-macro1","ecosystem":"crates.io","purl":"pkg:cargo/proc-macro1"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"}]}],"ecosystem_specific":{"affects":{"os":[],"functions":[],"arch":[]},"affected_functions":null},"database_specific":{"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0265.json","categories":["malicious"],"cvss":null,"informational":null}}],"schema_version":"1.9.0"}