Skip to content
Malicious Rust Packages Target Web3 Developers

Malicious Rust Packages Target Web3 Developers

First seen 4 Dec 2025, 15:42 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A malicious Rust crate named evm-units was discovered, aimed at stealing cryptocurrency from Web3 developers. It was downloaded 7,257 times before being removed from the Rust package registry, along with another package, uniswap-utils, which depended on it and had 7,441 downloads. Both packages have been taken down by the crates.io team.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Evm-units in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed