{"id":"RUSTSEC-2026-0263","title":"`tinymember` was removed from crates.io due to affiliation with malicious code","summary":"`tinymember` was removed from crates.io due to affiliation with malicious code","severity":"none","vendor":"tinymember","product":"tinymember","ecosystem":"rust","affected":["tinymember >= 0.0.0-0"],"published":"2026-08-20","updated":"2026-08-20","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0263","references":[{"url":"https://crates.io/crates/tinymember"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0263.html"},{"url":"https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"}],"tags":["osv","rust"],"ingestedAt":"2026-08-20T19:23:09.943Z","slug":"RUSTSEC-2026-0263","body":"## Overview\n\nWhile `tinymember` did not directly contain malicious code, it was owned by the\nsame user as `arone` and `aronenao`, which contained suspicious build scripts.\n\nThis crate had 2 versions published on 2026-08-18 that had a total of 27 downloads.\nThere were no crates depending on this crate on crates.io. The crate was removed\nfrom crates.io and the user account was locked.\n\n## Affected packages\n\n- `tinymember >= 0.0.0-0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}