VDB
GCVE-110-OSM-2026-10785
GCVE-110-OSM-2026-10785
Advisory PublishedCVSS 8.8/10
The build.rs script is a cross-platform dropper that downloads a binary from a hardcoded URL, writes it to a temporary directory (/tmp/rust-setup or temp_dir), and executes it using chmod/spawn on Unix and a hidden VBS/PowerShell launcher on Windows.
Downloads malicious payload from:
https://23[.254.165.112:9089/rust-crate_0.1.0 # Linux x86_64
https://23[.254.165.112:9089/rust-crate_0.2.0 # Windows x86_64
https://23[.254.165.112:9089/rust-crate_0.3.0 # macOS x86_64
https://23[.254.165.112:9089/rust-crate_0.4.0 # macOS ARM64
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | proc-macro-en | all (affected) | — |
Browse GCVE Records
867 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.