Skip to content

Commit d67f565

Browse files
Merge pull request #1758 from integer32llc/crates-io-security-ann
Malicious crates announcement
2 parents 5856609 + a669a9a commit d67f565

File tree

1 file changed

+37
-0
lines changed

1 file changed

+37
-0
lines changed
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
+++
2+
path = "2025/12/03/crates.io-malicious-crates-evm-units-and-uniswap-utils"
3+
title = "crates.io: Malicious crates evm-units and uniswap-utils"
4+
authors = ["Walter Pearce"]
5+
6+
[extra]
7+
team = "the crates.io team"
8+
team_url = "https://www.rust-lang.org/governance/teams/dev-tools#team-crates-io"
9+
+++
10+
11+
## Summary
12+
13+
On December 2nd, the crates.io team was notified by Olivia Brown from the [Socket Threat Research Team][socket] of two malicious crates which were downloading a payload that was likely attempting to steal cryptocurrency.
14+
15+
These crates were:
16+
17+
- `evm-units` - 13 versions published in April 2025, downloaded 7257 times
18+
- `uniswap-utils` - 14 versions published in April 2025, downloaded 7441 times, used `evm-units` as a dependency
19+
20+
## Actions taken
21+
22+
The user in question, `ablerust`, was immediately disabled, and the crates in question were deleted from crates.io shortly after. We have retained the malicious crate files for further analysis.
23+
24+
The deletions were performed at 22:01 UTC on December 2nd.
25+
26+
## Analysis
27+
28+
[Socket has published their analysis in a blog post](https://socket.dev/blog/malicious-rust-crate-evm-units-serves-cross-platform-payloads).
29+
30+
These crates had no dependent downstream crates on crates.io.
31+
32+
## Thanks
33+
34+
Our thanks to Olivia Brown from the [Socket Threat Research Team][socket] for reporting the crates. We also want to thank Carol Nichols from the crates.io team and Walter Pearce and Adam Harvey from the [Rust Foundation][foundation] for aiding in the response.
35+
36+
[foundation]: https://foundation.rust-lang.org/
37+
[socket]: https://www.socket.dev/

0 commit comments

Comments
 (0)