A new version of the append-only-vec crate was published with a direct dependency
on proc-macro1, which would execute a malicious build script.
The compromised version of this crate was published on 2026-08-20, and was removed approximately 107 minutes later.
The compromised crate version was used as part of a malware campaign targeted
at users of arrayref, which was downloaded 2,285 times before being removed;
see the arrayref advisory for more detail.
{
"license": "CC0-1.0"
}