Attacker Impact
onering 1.4.1 was reported as a compromised Rust crate release that used Cargo build-time execution to collect commit metadata and recent source diffs from the consuming project [S1][S2]. Teams that built a Rust workspace while resolving that release should treat developer and CI build environments as potentially exposed until they review logs, caches, and available credentials.
Root Cause
Cargo build scripts run during common Rust build workflows. Public reporting for this incident identifies the malicious release as onering 1.4.1 and also notes a compromised upstream git state around the incident window [S1][S3]. A repository dependency match is strong evidence that the project can resolve the malicious crate, but it does not prove the build script ran or that data left the environment.
Concrete Fixes
- Remove
onering1.4.1 and any dependency pinned to the compromised upstream git state. - Regenerate
Cargo.lockfrom a trusted registry state and rebuild CI images, devcontainers, Docker layers, and Cargo caches that may have cached the crate. - If the affected crate may have been built, review Cargo build logs and network egress, rotate credentials available to the build environment, and treat recent private source diffs as potentially exposed.
Covered by FixVibe
FixVibe's GitHub repo scans flag Cargo evidence for the compromised onering release or the known compromised upstream git state, with the file and remediation guidance.
