{"id":"MAL-2026-14333","title":"Malicious code in append_only_vec (crates.io)","summary":"Malicious code in append_only_vec (crates.io)","severity":"none","vendor":"append-only-vec","product":"append-only-vec","ecosystem":"rust","affected":["append-only-vec"],"published":"2026-08-20","updated":"2026-08-20","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-14333","references":[{"url":"https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/"},{"url":"https://github.com/rustsec/advisory-db/issues/3161"}],"tags":["osv","rust"],"ingestedAt":"2026-08-21T19:23:48.776Z","slug":"MAL-2026-14333","body":"## Overview\n\nappend-only-vec 0.1.9 was published to crates.io from the same maintainer account (droundy) as the trojanized arrayref and internment releases, which appears to be compromised. The release adds a dependency on an attacker-controlled crate whose build script downloads and executes an architecture-specific remote binary at build time from https://23.254.165.112:9089/, passing 23.254.165.112:443 as a command-and-control address. Part of a coordinated crates.io campaign on 2026-08-20. The malicious release has been removed from crates.io; earlier append-only-vec releases are unaffected.\n\n## Affected packages\n\n- `append-only-vec`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}