VYPR

cargo · Malicious package advisory

Malware

append-only-vec

GHSA-m9v3-f7h2-72cp

Malicious code in append_only_vec (crates.io)

Details

**Severity:** Critical

**Affected versions:** `= 0.1.9`

append-only-vec 0.1.9 was published to crates.io from the same maintainer account (droundy) as the trojanized arrayref and internment releases, which appears to be compromised. The release adds a dependency on an attacker-controlled crate whose build script downloads and executes an architecture-specific remote binary at build time from https://23.254.165.112:9089/, passing 23.254.165.112:443 as a command-and-control address. Part of a coordinated crates.io campaign on 2026-08-20. The malicious release has been removed from crates.io; earlier append-only-vec releases are unaffected.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/65e79a7e3677a36fcdbd109ea6e294bffc77f7db/osv/malicious/crates.io/append_only_vec/MAL-2026-14333.json))

**References:**
- https://github.com/rustsec/advisory-db/issues/3161
- https://github.com/ossf/malicious-packages/blob/65e79a7e3677a36fcdbd109ea6e294bffc77f7db/osv/malicious/crates.io/append_only_vec/MAL-2026-14333.json
- https://safedep.io/arrayref-proc-macro1-rust-build-time-malware
- https://github.com/advisories/GHSA-m9v3-f7h2-72cp

Compromised versions (1)

  • = 0.1.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.