The append-only-vec crate version 0.1.9 for the Rust programming language has been found to contain a rogue dependency that executes malicious code at compile time. When a developer compiles a project that depends on this crate, the malicious dependency connects to a command-and-control server and offers arbitrary code execution capabilities. This represents a build-time supply chain attack targeting Rust developers. The attack is similar in nature to other proc-macro and dependency-based supply chain attacks seen in the Rust ecosystem. Multiple security advisories have been published, including a RustSec advisory and analysis from StepSecurity and SafeDep. The attack is documented under RUSTSEC-2026-0262 and has been covered by the official Rust blog. Developers using this crate version should immediately remove the dependency and audit their build environments for signs of compromise.