CyberSecurityBoardThreat Intel · CVEs · Products
Malware

proc-macro1: Typosquatted Malicious Crate in Rust Supply Chain Attack

August 20, 2026

proc-macro1 is a typosquatted dependency of the legitimate proc-macro2 crate, used in a supply chain attack against Rust crates. Its build script downloads and executes a remote payload, disabling TLS validation and installing a backdoor that can steal credentials and persist on systems.