Skip to content

Malicious code in internment (crates.io)

Malware Published Aug 21, 2026 to the GitHub Advisory Database • Updated Aug 21, 2026

Package

cargo internment (Rust)

Affected versions

= 0.8.7

Patched versions

None

Description

internment 0.8.7 was published to crates.io from the same maintainer account (droundy) as the trojanized arrayref and append-only-vec releases, which appears to be compromised. The release adds a dependency on an attacker-controlled crate whose build script downloads and executes an architecture-specific remote binary at build time from https://23.254.165.112:9089/, passing 23.254.165.112:443 as a command-and-control address. Part of a coordinated crates.io campaign on 2026-08-20. The malicious release has been removed from crates.io; earlier internment releases are unaffected.


Credit: OpenSSF (source)

References

Published to the GitHub Advisory Database Aug 21, 2026
Reviewed Aug 21, 2026
Last updated Aug 21, 2026

EPSS score

Weaknesses

Embedded Malicious Code

The product contains code that appears to be malicious in nature. Learn more on MITRE.

GHSA ID

GHSA-mxq3-8c5w-crcm

Source code

No known source code
Improvements are not currently accepted on this advisory because this package is malware and has no patched versions. If there is something to change, please open an issue at https://github.com/github/advisory-database/issues.