


Perceptive Security
SOC/SIEM Consultancy

Malicious Rust Crate Delivers OS-Specific Malware to Web3 Developer Systems
Published:
3 december 2025 om 08:39:00
Alert date:
5 december 2025 om 08:03:22
Source:
thehackernews.com

Cybersecurity researchers discovered a malicious Rust package named 'evm-units' that targets Windows, macOS, and Linux systems. The crate was uploaded to crates.io by user 'ablerust' and masquerades as an Ethereum Virtual Machine unit helper tool. The malware is designed to execute stealthily on Web3 developer machines, representing a supply chain attack targeting the Rust ecosystem. The attack specifically targets developers in the Web3 space by disguising itself as a legitimate cryptocurrency development tool.
Technical details
Mitigation steps:
Affected products:
Rust Crates.io
Windows
macOS
Linux
Related links:
Related CVE's:
Related threat actors:
IOC's:
evm-units
This article was created with the assistance of AI technology by Perceptive.