A malicious Rust crate named evm-units has been found distributing OS-specific malware to Web3 developer systems.
The crate executed different payloads for Linux, macOS, and Windows and even checked for Qihoo 360 antivirus before running. More than 7K downloads occurred before removal.
The dependency chain through uniswap-utils made it even more impactful, highlighting ongoing risks in open-source supply chains.
💬 Curious how the community feels about strengthening package-repo trust and auditing.
Follow us for more security analysis and threat intelligence.
Source: https://thehackernews.com/2025/12/malicious-rust-crate-delivers-os.html
#Cybersecurity #Web3Security #RustLang #ThreatIntel #SupplyChainSecurity #MalwareAnalysis #Infosec #BlockchainSecurity