Loading cryptocurrency prices...

Malicious Rust Crates Steal Ethereum, Solana Wallet Keys

Malicious Rust Packages Found on Crates.io Stealing Solana and Ethereum Wallet Keys

  • Researchers found two malicious Rust packages disguised as a popular library targeting crypto wallet keys.
  • The compromised packages, named faster_log and async_println, had over 8,400 downloads before removal.
  • These packages stole Solana and Ethereum private keys from source code and sent them to a command-and-control server.
  • The crates copied legitimate code and documentation, making them appear trustworthy to developers.
  • The Rust package registry has removed the malicious crates and preserved user logs for investigation.

Cybersecurity researchers identified two harmful Rust packages distributed on crates.io that imitated a well-known logging library to steal private crypto wallet keys. The crates, called faster_log and async_println, appeared to be legitimate software, but their true purpose was to collect Solana and Ethereum wallet keys from developers’ source code.

- Advertisement -

According to Socket, a software supply chain security firm, the attacker used the aliases rustguruman and dumbnbased and published the crates on May 25, 2025. Together, these packages reached 8,424 downloads before being taken down. Security researcher Kirill Boychenko said the crates worked as logging tools but secretly searched for wallet keys and sent any found to a hardcoded web address controlled by the attacker.

“The malicious code was executed at runtime, when running or testing a project depending on them,” explained Walter Pearce from Crates.io. He added, “Notably, they did not execute any malicious code at build time. Except for their malicious payload, these crates copied the source code, features, and documentation of legitimate crates, using a similar name to them.” After a responsible disclosure, crates.io removed the packages and disabled both user accounts.

Socket described the tactic as a supply chain attack using typosquatting—where names similar to real packages deceive users. The fake packages kept all normal logging functions but added code that searched files with the .rs extension for wallet keys and uploaded them to a server hosted at mainnet.solana-rpc-pool.workers[.]dev.

Attackers also duplicated the README file and linked to the real fast_log GitHub project, making the bogus packages harder to identify. The use of a domain similar to Solana’s real Mainnet beta RPC endpoint further increased the risk of confusion.

- Advertisement -

Crates.io reported that the malicious crates did not have any dependent packages and the related GitHub accounts remain active. According to Boychenko, “A functional logger with a familiar name, copied design, and README can pass casual review, while a small routine posts private wallet keys to a threat actor-controlled C2 endpoint. Unfortunately, that is enough to reach developer laptops and CI.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Prosecutors Urge Judge to Uphold Tornado Cash Developer’s Conviction

Prosecutors urge the court to uphold the conviction of Roman Storm, co-founder of Tornado...

Block’s Cash App to Support USDC on Solana for Seamless Payments

Block's Cash App will support payments in USD Coin (USDC) on the Solana blockchain...

Bitcoin Drops Below $100K Amid Data Blackout Fears

Bitcoin Price dropped sharply below $100,000, reaching its lowest since May.October U.S. economic data...

Grayscale Files for IPO to List on NYSE Under Ticker GRAY

Grayscale Investments filed to go public on the New York Stock Exchange under the...

Shytoshi Kusama Prepares AI Boost for Shiba Inu Ecosystem Revival

Shytoshi Kusama, the lead developer of the Shiba Inu ecosystem, has been working quietly...
- Advertisement -

Must Read

7 Best Crypto To Invest In This Year

Investing in cryptocurrencies has become a popular way for people to diversify their investment portfolio and make potential profits.However, with so many cryptocurrencies available...