append-only-vec
Append-only, concurrent vector
Activity
- Latest release
- 3w ago
- Total releases
- 10
- Cadence
- ~2 months
- Last 12 months
- 2
Reach
- Downloads
- 4.5M
- Stars
- —
Details
- License
- MIT OR Apache-2.0
- First release
- Mar 08, 2022
| Version | Released | |
|---|---|---|
0.1.9
patch
2 CVEs
RUSTSEC-2026-0262
Aug 20, 2026
`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency A new version of the The compromised version of this crate was published on 2026-08-20, and was removed approximately 107 minutes later. The compromised crate version was used as part of a malware campaign targeted
at users of References Updated Aug 21, 2026 · Source: OSV.dev
MAL-2026-14333
Malware
Aug 20, 2026
Malicious code in append_only_vec (crates.io)
Critical
append-only-vec 0.1.9 was published to crates.io from the same maintainer account (droundy) as the trojanized arrayref and internment releases, which appears to be compromised. The release adds a dependency on an attacker-controlled crate whose build script downloads and executes an architecture-specific remote binary at build time from https://23.254.165.112:9089/, passing 23.254.165.112:443 as a command-and-control address. Part of a coordinated crates.io campaign on 2026-08-20. The malicious release has been removed from crates.io; earlier append-only-vec releases are unaffected. Affected versions
0.1.9
References Updated Aug 20, 2026 · Source: OSV.dev | ||
0.1.8
unknown
| ||
0.1.7
unknown
| ||
0.1.6
unknown
| ||
0.1.5
unknown
| ||
0.1.4
unknown
| ||
0.1.3
unknown
| ||
0.1.2
unknown
| ||
0.1.1
unknown
| ||
0.1.0
unknown
|