VDB
KO

MAL-2026-14333

Malicious code in append_only_vec (crates.io)

Details

append-only-vec 0.1.9 was published to crates.io from the same maintainer account (droundy) as the trojanized arrayref and internment releases, which appears to be compromised. The release adds a dependency on an attacker-controlled crate whose build script downloads and executes an architecture-specific remote binary at build time from https://23.254.165.112:9089/, passing 23.254.165.112:443 as a command-and-control address. Part of a coordinated crates.io campaign on 2026-08-20. The malicious release has been removed from crates.io; earlier append-only-vec releases are unaffected.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io / append-only-vec

No fixed version published yet for append-only-vec. Pin to a known-safe version or switch to an alternative.

References