- Reported
-
- Issued
-
- Package
-
aronenao
- Type
-
Vulnerability
- References
-
- Patched
-
no patched versions
Description
We identified that aronenao contained malicious code executed through a build
script.
This crate had 11 versions, with the most recent one being published at
2026-08-18. The crate was removed from crates.io and the user account was
locked.
This crate was used as part of a malware campaign targeted at users of
arrayref, which was downloaded 2,285 times before being removed; see
the arrayref advisory for more detail.
Advisory available under CC0-1.0
license.