RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0263

tinymember was removed from crates.io due to affiliation with malicious code

Reported
Issued
Package
tinymember
Type
Vulnerability
References
Patched
no patched versions

Description

While tinymember did not directly contain malicious code, it was owned by the same user as arone and aronenao, which contained suspicious build scripts.

This crate had 2 versions published on 2026-08-18 that had a total of 27 downloads. There were no crates depending on this crate on crates.io. The crate was removed from crates.io and the user account was locked.

Advisory available under CC0-1.0 license.