top of page

Malicious Rust Crate evm-units Serves Cross-Platform Payloads for Silent Execution

2 december 2025 om 22:09:46

socket.dev

Socket Threat Research Team discovered a malicious Rust package named evm-units that disguises itself as an EVM version helper utility. The malicious crate downloads and silently executes operating system-specific payloads targeting different platforms. The attack appears to be designed for crypto theft operations, leveraging the trust in legitimate-looking development tools. This represents a supply chain attack targeting Rust developers working with Ethereum Virtual Machine related projects. The cross-platform nature of the payloads suggests a sophisticated operation aimed at maximizing victim reach across different operating systems.

Related links:

Related CVE's:

No CVEs found in this article

Related threat actors:

No threat actors found in this article

Affected products:

Rustevm-units crate

IOC's:

evm-units

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page