{"id":"RUSTSEC-2026-0265","title":"`proc-macro1` was removed from crates.io due to malicious code","summary":"`proc-macro1` was removed from crates.io due to malicious code","severity":"none","vendor":"proc-macro1","product":"proc-macro1","ecosystem":"rust","affected":["proc-macro1 >= 0.0.0-0"],"published":"2026-08-20","updated":"2026-08-20","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0265","references":[{"url":"https://crates.io/crates/proc-macro1"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0265.html"},{"url":"https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"}],"tags":["osv","rust"],"ingestedAt":"2026-08-20T19:23:10.015Z","slug":"RUSTSEC-2026-0265","body":"## Overview\n\nIt was reported `proc-macro1` contained a build script that would download a\nmalicious payload.\n\nThis crate had two versions, both published at 2026-08-20 and it was used\nin a supply chain attack targeting popular crates. The crate was removed from\ncrates.io and related user accounts were locked.\n\nThanks to the Research Team at Nextron Systems GmbH for reporting this to the \nRust security response working group, and thanks to Emily Albini for coordinating\nwith the crates.io and infra-admin teams.\n\n## Affected packages\n\n- `proc-macro1 >= 0.0.0-0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}