{"id":"RUSTSEC-2026-0259","title":"`arone` was removed from crates.io due to malicious code","summary":"`arone` was removed from crates.io due to malicious code","severity":"none","vendor":"arone","product":"arone","ecosystem":"rust","affected":["arone >= 0.0.0-0"],"published":"2026-08-20","updated":"2026-08-20","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0259","references":[{"url":"https://crates.io/crates/arone"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0259.html"},{"url":"https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"}],"tags":["osv","rust"],"ingestedAt":"2026-08-20T19:23:09.801Z","slug":"RUSTSEC-2026-0259","body":"## Overview\n\nWe identified `arone` contained malicious code executed through a build script.\n\nThis crate had 7 versions, and the last was published at 2026-08-18 with no evidence\nof actual usage. The crate was removed from crates.io and the user account was\nlocked.\n\n## Affected packages\n\n- `arone >= 0.0.0-0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}