aovine
Append-only, concurrent vector
Activity
- Latest release
- 3w ago
- Total releases
- 4
- Cadence
- ~daily
- Last 12 months
- 4
Reach
- Downloads
- 0
Details
- License
- MIT OR Apache-2.0
- First release
- Aug 19, 2026
| Version | Released | |
|---|---|---|
0.1.4
patch
1 CVE
MAL-2026-14332
Malware
Aug 20, 2026
Malicious code in aovine (crates.io)
Critical
aovine is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign. References Updated Aug 20, 2026 · Source: OSV.dev | ||
0.1.3
patch
1 CVE
MAL-2026-14332
Malware
Aug 20, 2026
Malicious code in aovine (crates.io)
Critical
aovine is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign. References Updated Aug 20, 2026 · Source: OSV.dev | ||
0.1.1
patch
1 CVE
MAL-2026-14332
Malware
Aug 20, 2026
Malicious code in aovine (crates.io)
Critical
aovine is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign. References Updated Aug 20, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
MAL-2026-14332
Malware
Aug 20, 2026
Malicious code in aovine (crates.io)
Critical
aovine is a malicious crate published to crates.io as part of the coordinated build-time payload campaign on 2026-08-20 that trojanized arrayref, internment, and append-only-vec and published the proc-macro1 typosquat of proc-macro2. It was used as an attacker-controlled dependency carrying a build-script payload; building it results in the download and execution of a remote binary from https://23.254.165.112:9089/ with 23.254.165.112:443 as command and control. All versions have been removed from crates.io. The individual build script of this crate was not analyzed directly; its behavior is attributed from the campaign. References Updated Aug 20, 2026 · Source: OSV.dev |