PT-2026-83620 · Crates.Io · Proc-Macro1
Published
2026-08-20
·
Updated
2026-08-20
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
It was reported
proc-macro1 contained a build script that would download a
malicious payload.This crate had two versions, both published on 2026-08-20. The crate was
removed from crates.io and related user accounts were locked.
This crate was used as part of a malware campaign targeted at users of
arrayref, which was downloaded 2,285 times before being removed; see
the arrayref advisory for more detail.Thanks to the Research Team at Nextron Systems GmbH for reporting this to the
Rust security response working group, and thanks to Emily Albini for coordinating
with the crates.io and infra-admin teams.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Proc-Macro1