目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
crates.io active

aovine

MAL-2026-14332
2026-08-20 00:00:00
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in aovine (crates.io)

文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
下载量
数据源
暂无公开数据
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
crates.ioaovine*
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-20T00:00:00Z","published":"2026-08-20T00:00:00Z","schema_version":"1.7.4","id":"MAL-2026-14332","summary":"Malicious code in aovine (crates.io)","details":"aovine is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign.","affected":[{"package":{"ecosystem":"crates.io","name":"aovine"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"references":[{"type":"REPORT","url":"https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/"},{"type":"WEB","url":"https://github.com/rustsec/advisory-db/issues/3161"}],"credits":[{"name":"SafeDep","type":"FINDER","contact":["https://safedep.io"]},{"name":"jhobern","type":"REPORTER","contact":["https://github.com/jhobern"]}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0