Remove Malicious Rust Crate Targeting EVM Systems

03 Dec 2025

A malicious Rust crate masquerading as an Ethereum Virtual Machine (EVM) helper was removed from crates.io after accumulating over 7,000 downloads. The package targeted Windows, macOS, and Linux systems.

Details and Discovery

Cybersecurity researchers discovered the malicious crate, uploaded in mid-April 2025. A second package by the same author was pulled as a dependency by uniswap-utils and downloaded over 7,400 times.

According to Socket Security researcher Olivia Brown, the package executed a function get_evm_version() to decode and reach out to an external URL: download.videotalks.xyz. The resulting payload was written to system temp directories and executed differently on various operating systems.

  • On Linux, a script saved to /tmp/init was run using nohup.
  • On macOS, the script executed via osascript with nohup.
  • On Windows, a PowerShell script, init.ps1, was saved and executed.

Security Implications

The Rust crate contained a cross-platform loader initiating upon package use, implicating risk for systems without adequate protections. The crate checked for qhsafetray.exe, a process associated with Qihoo 360 antivirus. If not detected, a Visual Basic Script ran a PowerShell script hidden from users, suggesting China-focused targeting due to the profile of potentially crypto-related theft.

Remedies and Response

Both the malicious Rust crate and its dependency in uniswap-utils have been removed from crates.io. The incident highlights supply chain security vulnerabilities within software ecosystems, urging stronger scrutiny and safeguards.

Experts emphasize the importance of careful vetting of third-party packages to prevent such breaches.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6733598
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1426279
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
573606
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
462984
downloads

News and reviews for Desktop Windows

Remove Malicious Rust Crate Targeting EVM Systems

A Rust crate on crates.io posed security risks to EVM systems. Removed after 7,000+ downloads, it affected Windows, macOS, and Linux.

Read more

Windows Maintenance: Outdated Tasks to Skip

For efficient PC care, let Windows handle maintenance tasks like registry cleaning and driver updates.

Read more

Payday 3 Revamps Skills with New Update

Payday 3 introduces Skills 2.0 update with archetype skill trees, enhancing gameplay after initial system criticism.

Read more

Owlcat Games Delves into Investigation System

Owlcat Games reveals Investigation mechanics in Warhammer 40,000, exploring the Calixis Sector to uncover chaos and deliver justice.

Read more

Helldivers 2 Reduces File Size by 85% on PC

Helldivers 2 launches slim version on PC, cutting file size by 85%, enhancing load times via a beta test.

Read more

Forever Winter Update Adds Bar Management to Gameplay

Fun Dog Studios enhances Forever Winter with a unique bar management feature, enriching the extraction shooter experience.

Read more

ExplorerTabUtility Boosts Windows 11 File Explorer Tabs

ExplorerTabUtility enhances Windows 11 File Explorer by adding browser-like tab features, improving workflow and session restoration options.

Read more

Gamivo Elevates 2025's Top PC Games for Players

Gamivo highlights 2025's best PC games, impacting markets with discounted prices and broad player appeal.

Read more

Manor Lords Beta Patch Offers Major Improvements

Manor Lords introduces extensive gameplay updates in latest beta patch, enhancing player experience and matching its lowest price on Steam.

Read more

Prince of Persia Remake Set for January 2026 Launch

Ubisoft's Prince of Persia remake may release in January 2026, ending a 4-year wait, according to insider Tom Henderson.

Read more