Proc-macro1 malicious crate payload
Malware Activity
Updated: 20.08.2026 20:53
· First: 20.08.2026 20:53
· 📰 1 src / 1 articles
· H score: 29
A proc-macro1 typosquatted dependency executed a build-time payload during compilation, creating a credential-stealing risk for developers on Linux, Windows, and macOS. The payload reconstructed its infrastructure from base64-encoded fragments and chose host-matched code for each platform. It then targeted browser secrets from Chrome, Brave, and Edge while establishing persistence on the endpoint.