{"id":"RUSTSEC-2026-0175","summary":"`onering` 1.4.1 was removed from crates.io for malicious code","details":"A new version of the `onering` crate was published with code that attempted to\nexfiltrate both metadata and code from the project it was included within.\n\nOne malicious version was published on 2026-06-10, approximately six hours\nbefore removal. This crate has no dependencies on crates.io, and there is no\nevidence of actual usage of the compromised version.\n\nThanks to Charlie Eriksen for the report.","modified":"2026-06-10T19:15:05.267059444Z","published":"2026-06-10T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/onering"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0175.html"}],"affected":[{"package":{"name":"onering","ecosystem":"crates.io","purl":"pkg:cargo/onering"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.4.1"},{"fixed":"1.4.2-0"}]}],"ecosystem_specific":{"affected_functions":null,"affects":{"arch":[],"os":[],"functions":[]}},"database_specific":{"informational":null,"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0175.json","categories":["malicious"],"cvss":null}}],"schema_version":"1.7.5"}