Remove Malicious Rust Crate Targeting EVM Systems

03 Dec 2025

A malicious Rust crate masquerading as an Ethereum Virtual Machine (EVM) helper was removed from crates.io after accumulating over 7,000 downloads. The package targeted Windows, macOS, and Linux systems.

Details and Discovery

Cybersecurity researchers discovered the malicious crate, uploaded in mid-April 2025. A second package by the same author was pulled as a dependency by uniswap-utils and downloaded over 7,400 times.

According to Socket Security researcher Olivia Brown, the package executed a function get_evm_version() to decode and reach out to an external URL: download.videotalks.xyz. The resulting payload was written to system temp directories and executed differently on various operating systems.

  • On Linux, a script saved to /tmp/init was run using nohup.
  • On macOS, the script executed via osascript with nohup.
  • On Windows, a PowerShell script, init.ps1, was saved and executed.

Security Implications

The Rust crate contained a cross-platform loader initiating upon package use, implicating risk for systems without adequate protections. The crate checked for qhsafetray.exe, a process associated with Qihoo 360 antivirus. If not detected, a Visual Basic Script ran a PowerShell script hidden from users, suggesting China-focused targeting due to the profile of potentially crypto-related theft.

Remedies and Response

Both the malicious Rust crate and its dependency in uniswap-utils have been removed from crates.io. The incident highlights supply chain security vulnerabilities within software ecosystems, urging stronger scrutiny and safeguards.

Experts emphasize the importance of careful vetting of third-party packages to prevent such breaches.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7407937
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1701871
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
730748
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
491650
downloads

News and reviews for Desktop Windows

Dune: Awakening Adds Character Transfer Feature

Dune: Awakening update 1.2.40.0 introduces character transfers, enhancing player flexibility and experience.

Read more

Microsoft Expands Game Pass with Major Releases

Microsoft adds major titles like Death Stranding to Game Pass, enhancing the platform's offerings starting 2026-01-21.

Read more

Game Pass Adds Resident Evil Village; Big Releases Ahead

Game Pass updates: Resident Evil Village now available. Death Stranding Director's Cut and more coming soon, impacting player engagement.

Read more

Dune Awakening Expands to Consoles in 2026

Dune Awakening's console release in 2026 aims to capture PS5 and Xbox players, broadening its reach.

Read more

New Titles Including GamePass for January Launch

Xbox GamePass adds new games, including Warhammer and Death Stranding. Titles launch January 2023, expanding game library across platforms.

Read more

0patch Bridges Security Gap for Windows 10 Post-Support

0patch, offering micropatches, addresses security needs for Windows 10 after Microsoft's support ended. Costs may impact long-term use.

Read more

Big Hops Introduces Unique Gameplay by Luckshot Games

Big Hops by Luckshot Games adds unique mechanics to platformer genre with engaging movement and collectibles.

Read more

Project Reforged: Sonic Revamp with Alpha Demo Released

Project Reforged, by Besky, offers a fan remake of Sonic and the Black Knight with new levels and mechanics in its alpha demo.

Read more

Cor3 Countdown Hints at New Space FPS by Tarkov Lead

Cor3, linked to Escape From Tarkov's Buyanov, teases potential space FPS with a countdown ending on 2026-02-01.

Read more

PDFSIDER Malware Bypasses EDR via PDF24 Exploits

PDFSIDER backdoor exploits PDF24 vulnerabilities, evading EDR. Analyzed by Resecurity, it impacts endpoint defenses.

Read more