PT-2026-83617 · Crates.Io · Append-Only-Vec
Published
2026-08-20
·
Updated
2026-08-20
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
A new version of the
append-only-vec crate was published with a direct dependency
on proc-macro1, which would execute a malicious build script.The compromised version of this crate was published on 2026-08-20, and was
removed approximately 107 minutes later.
The compromised crate version was used as part of a malware campaign targeted
at users of
arrayref, which was downloaded 2,285 times before being removed;
see the arrayref advisory for more detail. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Append-Only-Vec