RUSTSEC-2026-0263

Source
https://rustsec.org/advisories/RUSTSEC-2026-0263
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0263.json
JSON Data
https://api.test.osv.dev/v1/vulns/RUSTSEC-2026-0263
Published
2026-08-20T12:00:00Z
Modified
2026-08-20T16:02:07.643054977Z
Summary
`tinymember` was removed from crates.io due to affiliation with malicious code
Details

While tinymember did not directly contain malicious code, it was owned by the same user as arone and aronenao, which contained suspicious build scripts.

This crate had 2 versions published on 2026-08-18 that had a total of 27 downloads. There were no crates depending on this crate on crates.io. The crate was removed from crates.io and the user account was locked.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / tinymember

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0

Ecosystem specific

{
    "affects": {
        "functions": [],
        "arch": [],
        "os": []
    },
    "affected_functions": null
}

Database specific

informational
null
cvss
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0263.json"
categories
[]