logo

Compromised Rust crate onering performs code exfiltration

ID: 2f0d17e0-04aa-54a4-bbf5-761077a31b65

STIX ID: report--2f0d17e0-04aa-54a4-bbf5-761077a31b65

Feed Name: Aikido Security's Blog

Threat Score
80/100

Date Published: 2026-06-10

Date Updated: 2026-07-24

...
...

On June 10, 2026, the Rust crate "onering" v1.4.1 was found to include a malicious build.rs that, when built, walks up from OUT_DIR to the consumer repository root, runs git to collect commit metadata and the diff of the most recent commit, and exfiltrates the stolen data disguised as a Sentry telemetry event to a remote Sentry ingest endpoint (URL and DSN provided). The compromise affects both the crates.io package and the maintainer's GitHub repository, leaks rolling source-code changes at build time without needing to call library functions, and includes clear IOCs and remediation/detection advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.