- Reported
-
- Issued
-
- Package
-
append-only-vec
(crates.io)
- Type
-
Vulnerability
- Categories
-
- References
-
- Patched
-
no patched versions
- Unaffected
-
Description
A new version of the append-only-vec crate was published with a direct dependency
on proc-macro1, which would execute a malicious build script.
This compromised version was published on 2026-08-20 and removed approximately
107 minutes later, with no evidence of actual usage.
Advisory available under CC0-1.0
license.