{"id":"RUSTSEC-2026-0264","title":"`proc-macro-en` was removed from crates.io due to malicious code","summary":"`proc-macro-en` was removed from crates.io due to malicious code","severity":"none","vendor":"proc-macro-en","product":"proc-macro-en","ecosystem":"rust","affected":["proc-macro-en >= 0.0.0-0"],"published":"2026-08-20","updated":"2026-08-20","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0264","references":[{"url":"https://crates.io/crates/proc-macro-en"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0264.html"},{"url":"https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"}],"tags":["osv","rust"],"ingestedAt":"2026-08-20T19:23:09.979Z","slug":"RUSTSEC-2026-0264","body":"## Overview\n\nWe identified that `proc-macro-en` contained the same build script as\n`proc-macro1` and it was part of the same supply chain attack.\n\nThis crate had one single version published at 2026-08-20. The crate was\nremoved from crates.io and related user account was locked.\n\n## Affected packages\n\n- `proc-macro-en >= 0.0.0-0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}