PkgRadar

Cargo · crates.io

keyhog-verifier

DNS / OAST exfiltration: matched "oast.fun"

Why PkgRadar flagged 0.5.40

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "oast.fun" · keyhog-verifier-0.5.40/src/oob/client.rs
highDNS / OAST exfiltrationmatched "oast.fun" · keyhog-verifier-0.5.40/src/oob/mod.rs
highDNS / OAST exfiltrationmatched "oast.fun" · keyhog-verifier-0.5.40/src/oob/session.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.40High risk552026-06-04
0.5.39High risk552026-06-04
0.5.37High risk552026-05-30

Block this in CI

PkgRadar gates keyhog-verifier (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]
keyhog-verifier — Cargo security scan | PkgRadar