FixVibe

high

Compromised Rust Crate 'onering' Performs Code Exfiltration

The Rust crate onering 1.4.1 was reported as compromised with build-time source-diff exfiltration behavior. FixVibe repo scans flag Cargo evidence for the malicious release or the compromised upstream git state.

CWE-506

Attacker Impact

onering 1.4.1 was reported as a compromised Rust crate release that used Cargo build-time execution to collect commit metadata and recent source diffs from the consuming project [S1][S2]. Teams that built a Rust workspace while resolving that release should treat developer and CI build environments as potentially exposed until they review logs, caches, and available credentials.

Root Cause

Cargo build scripts run during common Rust build workflows. Public reporting for this incident identifies the malicious release as onering 1.4.1 and also notes a compromised upstream git state around the incident window [S1][S3]. A repository dependency match is strong evidence that the project can resolve the malicious crate, but it does not prove the build script ran or that data left the environment.

Concrete Fixes

  • Remove onering 1.4.1 and any dependency pinned to the compromised upstream git state.
  • Regenerate Cargo.lock from a trusted registry state and rebuild CI images, devcontainers, Docker layers, and Cargo caches that may have cached the crate.
  • If the affected crate may have been built, review Cargo build logs and network egress, rotate credentials available to the build environment, and treat recent private source diffs as potentially exposed.

Covered by FixVibe

FixVibe's GitHub repo scans flag Cargo evidence for the compromised onering release or the known compromised upstream git state, with the file and remediation guidance.