—
RUSTSEC-2026-0265
`proc-macro1` was removed from crates.io due to malicious code
Details
It was reported `proc-macro1` contained a build script that would download a malicious payload.
This crate had two versions, both published at 2026-08-20 and it was used in a supply chain attack targeting popular crates. The crate was removed from crates.io and related user accounts were locked.
Thanks to the Research Team at Nextron Systems GmbH for reporting this to the Rust security response working group, and thanks to Emily Albini for coordinating with the crates.io and infra-admin teams.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io / proc-macro1
Introduced in:
0.0.0-0 No fixed version published yet for proc-macro1. Pin to a known-safe version or switch to an alternative.