Compromised Rust Crate With 18,000+ Downloads Steals Source Code During Builds

A malicious update to the Rust crate called onering has been discovered, which exfiltrates source code changes from developers’ machines during the build process. Security researchers identified this behavior in version 1.4.1 of the package on June 10, 2026. The onering crate, designed as a high-throughput synchronous queue and channels library, has garnered over 18,000 […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: