Malicious code in internment (crates.io)
Malware
Published
Aug 21, 2026
to the GitHub Advisory Database
•
Updated Aug 21, 2026
Description
Published to the GitHub Advisory Database
Aug 21, 2026
Reviewed
Aug 21, 2026
Last updated
Aug 21, 2026
internment 0.8.7 was published to crates.io from the same maintainer account (droundy) as the trojanized arrayref and append-only-vec releases, which appears to be compromised. The release adds a dependency on an attacker-controlled crate whose build script downloads and executes an architecture-specific remote binary at build time from https://23.254.165.112:9089/, passing 23.254.165.112:443 as a command-and-control address. Part of a coordinated crates.io campaign on 2026-08-20. The malicious release has been removed from crates.io; earlier internment releases are unaffected.
Credit: OpenSSF (source)
References