← Terug naar overzicht

The append-only-vec crate version 0.1.9 for the Rust programming language has been found to contain a rogue dependency that executes malicious code at compile time. When a developer compiles a project that depends on this crate, the malicious dependency connects to a command-and-control server and offers arbitrary code execution capabilities. This represents a build-time supply chain attack targeting Rust developers. The attack is similar in nature to other proc-macro and dependency-based supply chain attacks seen in the Rust ecosystem. Multiple security advisories have been published, including a RustSec advisory and analysis from StepSecurity and SafeDep. The attack is documented under RUSTSEC-2026-0262 and has been covered by the official Rust blog. Developers using this crate version should immediately remove the dependency and audit their build environments for signs of compromise.

Affected products

  • Rust
  • append-only-vec crate 0.1.9

Related CVE's

  • CVE-2026-77650

Categories

  • Ransomware & Malware
  • Supply Chain & Dependencies