Malicious Rust Packages Target Web3 Developers

Malicious Rust Packages Target Web3 Developers

First seen 4 Dec 2025, 15:42 UTC CointrustFeeds2.Feedburner 85% similarity 26.3

Article Content

Browse articles
ThreatCluster

A malicious Rust crate named evm-units was discovered, aimed at stealing cryptocurrency from Web3 developers. It was downloaded 7,257 times before being removed from the Rust package registry, along with another package, uniswap-utils, which depended on it and had 7,441 downloads. Both packages have been taken down by the crates.io team.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story