VYPR

cargo · Malicious package advisory

Malware

aronenao

GHSA-vqfg-g9r4-x39f

Malicious code in aronenao (crates.io)

Details

**Severity:** Critical

**Affected versions:** `> 0`

aronenao is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/65e79a7e3677a36fcdbd109ea6e294bffc77f7db/osv/malicious/crates.io/aronenao/MAL-2026-14335.json))

**References:**
- https://github.com/rustsec/advisory-db/issues/3161
- https://github.com/ossf/malicious-packages/blob/65e79a7e3677a36fcdbd109ea6e294bffc77f7db/osv/malicious/crates.io/aronenao/MAL-2026-14335.json
- https://safedep.io/arrayref-proc-macro1-rust-build-time-malware
- https://github.com/advisories/GHSA-vqfg-g9r4-x39f

Compromised versions (1)

  • > 0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.