{"id":"MAL-2026-14339","title":"Malicious code in proc_macro_en (crates.io)","summary":"Malicious code in proc_macro_en (crates.io)","severity":"none","vendor":"proc-macro-en","product":"proc-macro-en","ecosystem":"rust","affected":["proc-macro-en"],"published":"2026-08-20","updated":"2026-08-20","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-14339","references":[{"url":"https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/"},{"url":"https://github.com/rustsec/advisory-db/issues/3161"}],"tags":["osv","rust"],"ingestedAt":"2026-08-21T19:23:49.027Z","slug":"MAL-2026-14339","body":"## Overview\n\nproc-macro-en is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign.\n\n## Affected packages\n\n- `proc-macro-en`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}