Skip to content

Malicious code in proc_macro_en (crates.io)

Malware Published Aug 21, 2026 to the GitHub Advisory Database • Updated Aug 21, 2026

Package

cargo proc-macro-en (Rust)

Affected versions

> 0

Patched versions

None

Description

proc-macro-en is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign.


Credit: OpenSSF (source)

References

Published to the GitHub Advisory Database Aug 21, 2026
Reviewed Aug 21, 2026
Last updated Aug 21, 2026

EPSS score

Weaknesses

Embedded Malicious Code

The product contains code that appears to be malicious in nature. Learn more on MITRE.

GHSA ID

GHSA-4v73-396v-6ph9

Source code

No known source code
Improvements are not currently accepted on this advisory because this package is malware and has no patched versions. If there is something to change, please open an issue at https://github.com/github/advisory-database/issues.