top of page
perceptive_background_267k.jpg

Malicious Rust crate evm-units disguised as an EVM version helper downloads and silently executes OS-specific payloads likely aimed at crypto theft.

Published:

2 December 2025 at 22:09:46

Alert date:

5 December 2025 at 08:03:23

Source:

socket.dev

Click to open the original link from this advisory

Socket Threat Research Team discovered a malicious Rust package named evm-units that disguises itself as an Ethereum Virtual Machine (EVM) version helper utility. The malicious crate downloads and silently executes operating system-specific payloads across multiple platforms. The attack appears to be designed for cryptocurrency theft operations. This represents a supply chain attack targeting the Rust ecosystem, similar to attacks seen in other package repositories. The malware's cross-platform capabilities and silent execution make it particularly dangerous for developers who might unknowingly include it in their projects.

Technical details

Mitigation steps:

Affected products:

Rust Crates
evm-units

Related links:

Related CVE's:

Related threat actors:

IOC's:

evm-units

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page