---
id: RUSTSEC-2026-0265
title: '`proc-macro1` was removed from crates.io due to malicious code'
summary: '`proc-macro1` was removed from crates.io due to malicious code'
severity: none
vendor: proc-macro1
product: proc-macro1
ecosystem: rust
affected:
  - proc-macro1 >= 0.0.0-0
published: '2026-08-20'
updated: '2026-08-20'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0265'
references:
  - url: 'https://crates.io/crates/proc-macro1'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0265.html'
  - url: 'https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref'
tags:
  - osv
  - rust
ingestedAt: '2026-08-20T19:23:10.015Z'
---

## Overview

It was reported `proc-macro1` contained a build script that would download a
malicious payload.

This crate had two versions, both published at 2026-08-20 and it was used
in a supply chain attack targeting popular crates. The crate was removed from
crates.io and related user accounts were locked.

Thanks to the Research Team at Nextron Systems GmbH for reporting this to the 
Rust security response working group, and thanks to Emily Albini for coordinating
with the crates.io and infra-admin teams.

## Affected packages

- `proc-macro1 >= 0.0.0-0`

## Remediation

Refer to the advisory for the patched release.
