


Perceptive Security
SOC/SIEM Consultancy

Malicious Rust crate evm-units disguised as an EVM version helper downloads and silently executes OS-specific payloads likely aimed at crypto theft.
Published:
2 December 2025 at 22:09:46
Alert date:
5 December 2025 at 08:03:23
Source:
socket.dev

Socket Threat Research Team discovered a malicious Rust package named evm-units that disguises itself as an Ethereum Virtual Machine (EVM) version helper utility. The malicious crate downloads and silently executes operating system-specific payloads across multiple platforms. The attack appears to be designed for cryptocurrency theft operations. This represents a supply chain attack targeting the Rust ecosystem, similar to attacks seen in other package repositories. The malware's cross-platform capabilities and silent execution make it particularly dangerous for developers who might unknowingly include it in their projects.
Technical details
Mitigation steps:
Affected products:
Rust Crates
evm-units
Related links:
Related CVE's:
Related threat actors:
IOC's:
evm-units
This article was created with the assistance of AI technology by Perceptive.