Malicious code in proc_macro_en (crates.io)
Malware
Published
Aug 21, 2026
to the GitHub Advisory Database
•
Updated Aug 21, 2026
Description
Published to the GitHub Advisory Database
Aug 21, 2026
Reviewed
Aug 21, 2026
Last updated
Aug 21, 2026
proc-macro-en is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign.
Credit: OpenSSF (source)
References