Skip to content

Malicious code in aovine (crates.io)

Malware Published Aug 21, 2026 to the GitHub Advisory Database

Package

cargo aovine (Rust)

Affected versions

> 0

Patched versions

None

Description

aovine is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign.


Credit: OpenSSF (source)

References

Published to the GitHub Advisory Database Aug 21, 2026
Reviewed Aug 21, 2026

EPSS score

Weaknesses

Embedded Malicious Code

The product contains code that appears to be malicious in nature. Learn more on MITRE.

GHSA ID

GHSA-r47g-vj55-h745

Source code

No known source code
Improvements are not currently accepted on this advisory because this package is malware and has no patched versions. If there is something to change, please open an issue at https://github.com/github/advisory-database/issues.