CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Products

append-only-vec: Rust Crate Affected by Malicious Release

August 20, 2026

append-only-vec is a Rust crate that had a malicious version (0.1.9) published during the supply chain attack. The release included a dependency on proc-macro1 and was removed within 107 minutes. Users should ensure they are not using the compromised version.