{"id":"RUSTSEC-2026-0175","title":"`onering` 1.4.1 was removed from crates.io for malicious code","summary":"`onering` 1.4.1 was removed from crates.io for malicious code","severity":"none","vendor":"onering","product":"onering","ecosystem":"rust","affected":["onering >= 1.4.1, < 1.4.2-0"],"patched":["onering 1.4.2-0"],"published":"2026-06-10","updated":"2026-09-22","sourceUpdated":"2026-09-22T15:16:11Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0175","references":[{"url":"https://crates.io/crates/onering"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0175.html"}],"tags":["osv","rust"],"ingestedAt":"2026-09-24T07:16:01.870Z","slug":"RUSTSEC-2026-0175","body":"## Overview\n\nA new version of the `onering` crate was published with code that attempted to\nexfiltrate both metadata and code from the project it was included within.\n\nOne malicious version was published on 2026-06-10, approximately six hours\nbefore removal. This crate has no dependencies on crates.io, and there is no\nevidence of actual usage of the compromised version.\n\nThanks to Charlie Eriksen for the report.\n\n## Affected packages\n\n- `onering >= 1.4.1, < 1.4.2-0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `onering 1.4.2-0`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}