Two malicious packages were discovered in the Rust repository crates.io

Rust language developers have warned about the discovery of malicious code in the faster_log and async_println packages in the crates.io repository. The packages were uploaded on May 25 and have since been downloaded 8,424 times.

To distribute the packages, the attackers exploited their similarity to the names of popular legitimate packages (for example, using faster_log instead of fast_log), supplying modified clones and hoping that users would overlook the minor differences when finding the package through search or selecting from a list. Both packages offered functions used for working with logs in applications.

The malicious code was triggered when running or testing projects that used the faster_log and async_println packages as dependencies (the malicious code did not activate during the build stage). The malicious activity focused on searching processed logs for private keys of Solana and Ethereum cryptocurrencies, as well as character combinations resembling keys. The found keys were sent to an external server attacker's server.

Additionally, there is a warning about a new wave of phishing targeting those maintaining packages in the PyPI directory. Users are being sent messages purportedly from PyPI, requesting email confirmation under the threat of account suspension. The message contains a link to a confirmation form that leads to domain pypi-mirror.org, registered by the attackers.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster