---
id: MAL-2026-14339
title: Malicious code in proc_macro_en (crates.io)
summary: Malicious code in proc_macro_en (crates.io)
severity: none
vendor: proc-macro-en
product: proc-macro-en
ecosystem: rust
affected:
  - proc-macro-en
published: '2026-08-20'
updated: '2026-08-20'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-14339'
references:
  - url: 'https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/'
  - url: 'https://github.com/rustsec/advisory-db/issues/3161'
tags:
  - osv
  - rust
ingestedAt: '2026-08-21T19:23:49.027Z'
---

## Overview

proc-macro-en is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign.

## Affected packages

- `proc-macro-en`

## Remediation

Refer to the advisory for the patched release.
