---
id: RUSTSEC-2026-0264
title: '`proc-macro-en` was removed from crates.io due to malicious code'
summary: '`proc-macro-en` was removed from crates.io due to malicious code'
severity: none
vendor: proc-macro-en
product: proc-macro-en
ecosystem: rust
affected:
  - proc-macro-en >= 0.0.0-0
published: '2026-08-20'
updated: '2026-08-20'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0264'
references:
  - url: 'https://crates.io/crates/proc-macro-en'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0264.html'
  - url: 'https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref'
tags:
  - osv
  - rust
ingestedAt: '2026-08-20T19:23:09.979Z'
---

## Overview

We identified that `proc-macro-en` contained the same build script as
`proc-macro1` and it was part of the same supply chain attack.

This crate had one single version published at 2026-08-20. The crate was
removed from crates.io and related user account was locked.

## Affected packages

- `proc-macro-en >= 0.0.0-0`

## Remediation

Refer to the advisory for the patched release.
