---
id: RUSTSEC-2026-0263
title: '`tinymember` was removed from crates.io due to affiliation with malicious code'
summary: '`tinymember` was removed from crates.io due to affiliation with malicious code'
severity: none
vendor: tinymember
product: tinymember
ecosystem: rust
affected:
  - tinymember >= 0.0.0-0
published: '2026-08-20'
updated: '2026-08-20'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0263'
references:
  - url: 'https://crates.io/crates/tinymember'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0263.html'
  - url: 'https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref'
tags:
  - osv
  - rust
ingestedAt: '2026-08-20T19:23:09.943Z'
---

## Overview

While `tinymember` did not directly contain malicious code, it was owned by the
same user as `arone` and `aronenao`, which contained suspicious build scripts.

This crate had 2 versions published on 2026-08-18 that had a total of 27 downloads.
There were no crates depending on this crate on crates.io. The crate was removed
from crates.io and the user account was locked.

## Affected packages

- `tinymember >= 0.0.0-0`

## Remediation

Refer to the advisory for the patched release.
