RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0266

internment 0.8.7 was removed from crates.io due to a malicious dependency

Reported
Issued
Package
internment (crates.io)
Type
Vulnerability
Categories
References
Patched
no patched versions
Unaffected
  • <=0.8.6

Description

A new version of the internment crate was published with a direct dependency on proc-macro1, which would execute a malicious build script.

The compromised version of this crate was published on 2026-08-20, and was removed approximately 90 minutes later.

The compromised version was used as part of a malware campaign targeted at users of arrayref, which was downloaded 2,285 times before being removed; see the arrayref advisory for more detail.

Advisory available under CC0-1.0 license.