Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Cross-Platform Malware Hidden in Rust Package Targets Web3 Developers

Cross-Platform Malware Hidden in Rust Package Targets Web3 Developers

Malicious Crate Poses as EVM Utility to Breach Multiple Systems

Kelly Cromley by Kelly Cromley
Dec 3, 2025
in Ethereum News, Market News, News
Reading Time: 2 mins read
0
Malware

Cybersecurity analysts have reported the discovery of a harmful Rust package capable of infecting Windows, macOS, and Linux environments. The malicious crate was said to masquerade as a tool associated with Ethereum Virtual Machine utilities, allowing it to operate covertly on developer systems. Researchers noted that the package was crafted in a way that allowed it to blend into legitimate workflows within the Web3 development ecosystem.

The Rust crate, identified as evm-units, was initially published on crates.io in mid-April 2025 by an author using the handle ablerust. Over the following eight months, it accumulated more than 7,000 downloads. A second package tied to the same author, uniswap-utils, listed evm-units as a dependency and recorded more than 7,400 downloads. Both packages have since been removed from the repository.

Security researchers explained that the package behaved differently depending on the operating system and whether a particular antivirus tool was active. The malware was said to retrieve a payload, place it in the system’s temporary directory, and execute it silently. To the developer, the crate appeared to return an Ethereum version number, disguising its true behavior.

Targeting Users of a Popular Chinese Antivirus Tool

Investigators highlighted that the malware intentionally checked for the presence of qhsafetray.exe, a process linked to 360 Total Security, an antivirus application developed by the Chinese company Qihoo 360. This focus was viewed as an unusual and explicit targeting indicator. Researchers suggested that the emphasis on a China-based security product aligned with common crypto-theft patterns, given the prominence of cryptocurrency activity in Asian markets.

The harmful activity was embedded within a seemingly harmless function called get_evm_version(). When executed, the function contacted an external domain to download a second-stage payload tailored to the victim’s operating system.

  • On Linux, the crate downloaded a script, stored it as /tmp/init, and launched it in the background via the nohup command, granting the attacker remote control.
  • On macOS, it retrieved a file named init and executed it using osascript alongside nohup in the background.
  • On Windows, it downloaded a PowerShell script labeled init.ps1 into the temporary directory, then scanned for the qhsafetray.exe process. If the process was absent, the malware generated a Visual Basic Script wrapper to run a hidden PowerShell session without displaying a window. If the antivirus process was found, execution shifted slightly but still proceeded through PowerShell.

This OS-specific branching allowed the attacker to maintain persistence and minimize the likelihood of detection across different environments.

Web3 Developers Positioned as Primary Targets

Researchers indicated that references to Ethereum and Uniswap strongly suggested that the incident was crafted to infiltrate Web3-related supply chains. By branding the malicious crates as utilities for Ethereum development, the threat actor was positioned to target developers or projects involved with decentralized applications and blockchain tooling.

According to the analysis, the individual behind the packages embedded a cross-platform loader inside what appeared to be routine helper functions. The risk was amplified because the malicious dependency was incorporated into another widely used package, allowing the code to run automatically during initialization without requiring developers to call any suspicious functions.

Overall, the incident underscored the growing threat of supply-chain attacks targeting open-source ecosystems, particularly those connected to blockchain development. Security specialists emphasized the importance of closer scrutiny over package sources and dependencies, especially within sectors where financial incentives drive increasingly sophisticated adversary behavior.

Previous Post

AscendEX Partners With Dmail AI to Boost Web3 Messaging Security

Next Post

Nomis and Owlto Boost Web3 Security With Reputation-Based Interoperability

Related Posts

bullfrog power

Bullfrog Power Launches Blockchain Tokens to Boost Sustainability Trust

by Kelly Cromley
Dec 5, 2025
0

Bullfrog Power has introduced a new initiative aimed at strengthening transparency in environmental reporting by issuing tokenized sustainability certificates on...

titan trading platform

Titan–Zeni Alliance Aims to Elevate AI-Powered Crypto Trading

by Kelly Cromley
Dec 5, 2025
0

Titan Trading Platform has revealed a strategic collaboration with Zeni.io, a provider specializing in data infrastructure tailored for AI agents....

agi open network

AON and Infiblue World Unite to Advance AI-Driven Web3 Social Tools

by Kelly Cromley
Dec 5, 2025
0

AGI Open Network (AON), a prominent decentralized ecosystem for building AI agents, has entered a strategic partnership with Infiblue World,...

N3XT

Blockchain-Driven N3XT Bank Promises Instant 24/7 Dollar Payments

by Kelly Cromley
Dec 4, 2025
0

A new player in financial services, N3XT, has formally launched with the goal of reshaping business-to-business payments through blockchain technology....

chaingpt

ChainGPT Integrates Into Carbon Browser to Simplify Web3 Access

by Kelly Cromley
Dec 4, 2025
0

ChainGPT and Carbon Browser have jointly rolled out a browser-level AI assistant that both teams describe as a meaningful upgrade...

my-green-condo

MGCOne Patent Signals a Major Shift in Community Management

by Kelly Cromley
Dec 4, 2025
0

My Green Condo Inc. reported that the United States Patent and Trademark Office has awarded U.S. Patent No. 12443952 for...

Next Post
owlto finance

Nomis and Owlto Boost Web3 Security With Reputation-Based Interoperability

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

bullfrog power
Market News

Bullfrog Power Launches Blockchain Tokens to Boost Sustainability Trust

by Kelly Cromley
Dec 5, 2025
titan trading platform
Market News

Titan–Zeni Alliance Aims to Elevate AI-Powered Crypto Trading

by Kelly Cromley
Dec 5, 2025
agi open network
Market News

AON and Infiblue World Unite to Advance AI-Driven Web3 Social Tools

by Kelly Cromley
Dec 5, 2025
N3XT
Market News

Blockchain-Driven N3XT Bank Promises Instant 24/7 Dollar Payments

by Kelly Cromley
Dec 4, 2025
chaingpt
Market News

ChainGPT Integrates Into Carbon Browser to Simplify Web3 Access

by Kelly Cromley
Dec 4, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.