Remove Malicious Rust Crate Targeting EVM Systems

03 Dec 2025

A malicious Rust crate masquerading as an Ethereum Virtual Machine (EVM) helper was removed from crates.io after accumulating over 7,000 downloads. The package targeted Windows, macOS, and Linux systems.

Details and Discovery

Cybersecurity researchers discovered the malicious crate, uploaded in mid-April 2025. A second package by the same author was pulled as a dependency by uniswap-utils and downloaded over 7,400 times.

According to Socket Security researcher Olivia Brown, the package executed a function get_evm_version() to decode and reach out to an external URL: download.videotalks.xyz. The resulting payload was written to system temp directories and executed differently on various operating systems.

  • On Linux, a script saved to /tmp/init was run using nohup.
  • On macOS, the script executed via osascript with nohup.
  • On Windows, a PowerShell script, init.ps1, was saved and executed.

Security Implications

The Rust crate contained a cross-platform loader initiating upon package use, implicating risk for systems without adequate protections. The crate checked for qhsafetray.exe, a process associated with Qihoo 360 antivirus. If not detected, a Visual Basic Script ran a PowerShell script hidden from users, suggesting China-focused targeting due to the profile of potentially crypto-related theft.

Remedies and Response

Both the malicious Rust crate and its dependency in uniswap-utils have been removed from crates.io. The incident highlights supply chain security vulnerabilities within software ecosystems, urging stronger scrutiny and safeguards.

Experts emphasize the importance of careful vetting of third-party packages to prevent such breaches.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7456204
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1714817
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
736991
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
493053
downloads

News and reviews for Desktop Windows

Open-source Apps Offer Cost-effective Windows Solutions

Explore five open-source Windows apps enhancing productivity and saving costs, offering full features and flexibility.

Read more

TrueSight Driver Exploited to Avoid Windows Security

Hackers misuse TrueSight to bypass Windows security tools, leading to ransomware deployment.

Read more

Crimson Desert Goes Gold, Release Set for March 19

Crimson Desert has gone gold, set to launch on 2026-03-19. Pearl Abyss confirms the game is ready, promising a rich adventure in Pywel.

Read more

Death Stranding Director's Cut Now on Xbox Game Pass

Death Stranding Director's Cut is now available on Xbox Game Pass for console and PC users, enhancing gameplay options.

Read more

MIO Launches with Unique Metroidvania Experience

MIO debuts with a blend of exploration and combat, offering a new indie Metroidvania experience on The Vessel. Available now for $17.59.

Read more

Windows 11 Update KB5074109 Causes Black Screen Issues

KB5074109 update for Windows 11 leads to black screens, Outlook crashes. Microsoft investigating. Next Patch Tuesday: 2026-02-10.

Read more

Outfit7 Launches PlayValley for PC and Mobile Games

Outfit7 unveils PlayValley, a division for creating PC and mobile games, debuting on Steam by 2026-Q2.

Read more

Arknights: Endfield Launches Globally on 2026-01-22

Arknights: Endfield is set for a global release on January 22, 2026. Preloading is advisable to avoid connectivity issues.

Read more

Cassette Boy Launches on Steam with Engaging Puzzle Mechanics

Cassette Boy debuts on Steam, offering a unique 2D/3D puzzle experience. Explore innovative mechanics and hidden secrets in this engaging game.

Read more

Dune: Awakening Adds Character Transfer Feature

Dune: Awakening update 1.2.40.0 introduces character transfers, enhancing player flexibility and experience.

Read more