RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0265

proc-macro1 was removed from crates.io due to malicious code

Reported
Issued
Package
proc-macro1
Type
Vulnerability
Categories
References
Patched
no patched versions

Description

It was reported proc-macro1 contained a build script that would download a malicious payload.

This crate had two versions, both published at 2026-08-20 and it was used in a supply chain attack targeting popular crates. The crate was removed from crates.io and related user accounts were locked.

Thanks to the Research Team at Nextron Systems GmbH for reporting this to the Rust security response working group, and thanks to Emily Albini for coordinating with the crates.io and infra-admin teams.

Advisory available under CC0-1.0 license.