Four malicious packages were identified in the Rust repository crates.io

Rust language developers have warned about the detection of the packages finch-rust, sha-rust, evm-units, and uniswap-utils in the crates.io repository, which contain malicious code.

The evm-units package included code for downloading malicious components aimed at stealing cryptocurrency. The malicious package was uploaded in April 2025 and was downloaded 7,257 times. The uniswap-utils package was also uploaded in April, downloaded 7,441 times, and used evm-units as a dependency. The malicious code was activated when calling the get_evm_version() function and led to the download of external code from the link "https://download[.]videotalks[.]xyz/gui/6dad3/...". On Linux and macOS, an init script was downloaded and executed, while on Windows, it was init.ps1.

The sha-rust package was uploaded to the directory on November 20, downloaded 153 times, and contained code for searching and sending sensitive data externally. server The finch-rust package included original code from the finch package, to which a call to the function "sha_rust::from_str()" was added, which executed an obfuscated handler sending system information, environment variables, as well as the contents of config.toml, id.json, and files with the " .env" extension (e.g., production.env, staging.env, and dev.env with access tokens) to the server "https://rust-docs-build[.]vercel[.]app/api/v1".

On November 25, the finch-rust package was also uploaded to crates.io, using sha-rust as a dependency and created for a type-squatting attack on users of the legitimate finch package, assuming that users would not notice the difference in the name, finding the package through search or selecting it from a list.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster