Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed

Cybersecurity researchers have uncovered two malicious Rust crates that mimic a trusted library, ultimately stealing Solana and Ethereum wallet keys. With a total of 8,424 downloads, these crates underscore the growing threat to open-source software supply chains.

Key Takeaways:

  • Two crates, faster_log and async_println, impersonate a legitimate library.
  • Cybercriminals targeted Solana and Ethereum wallet keys.
  • The malicious crates were collectively downloaded 8,424 times.
  • They were published on May 25, 2025, by aliases “rustguruman” and “dumbnbased.”
  • This incident highlights the software supply chain’s vulnerability.

The Discovery

Cybersecurity researchers recently identified two malicious Rust crates that disguise themselves as a legitimate library. Known as faster_log and async_println, these crates first caught attention when they appeared suspiciously similar to the established fast_log library. The threat actors behind this scheme, operating under the aliases “rustguruman” and “dumbnbased,” published their crates on May 25, 2025.

The Malicious Method

Instead of offering the same logging functionalities as the authentic fast_log library, these impostor crates incorporated code designed to steal cryptocurrency wallet keys. Solana and Ethereum keys were specifically targeted, exposing unsuspecting developers—and potentially their users—to significant risk. This deceptive approach underscores the importance of scrutinizing dependencies and packages before integrating them into projects.

Impact and Download Figures

According to researchers, the faster_log and async_println crates were collectively downloaded 8,424 times. Such download numbers point to possible widespread exposure among developers who may unknowingly incorporate these dangerous crates into their codebases. In a realm where digital assets and projects require frequent updates, new vulnerabilities can spread rapidly.

Actor’s Aliases and Publication Timeline

Appearing under the aliases “rustguruman” and “dumbnbased,” these malicious actors took advantage of open-source ecosystems’ trust-based model. The crates’ release on May 25, 2025, underscores how quickly threats can disseminate once malicious code is added to a package repository.

Broader Security Implications

This incident signals a larger issue within software development communities. As open-source repositories grow, verifying publisher credibility and analyzing code thoroughly become ever more crucial. Attacks like this illustrate how malicious actors can target the supply chain, putting both developers and end-users at risk.

Next Steps

Such attacks remind us that due diligence is key to securing projects. Developers should carefully vet any library or package they incorporate, monitor for unusual activities, and keep an eye on security advisories. Only through vigilance can the open-source community preserve the integrity and safety of its software repositories.

More from World

Yiwu's Journey: From Gala to Global Fame
by Travel And Tour World
18 hours ago
2 mins read
Yiwu Transforms from Spring Festival Gala Spotlight to Travel Hotspot: How China’s Small Commodities Capital Became the Unlikely Tourism Giant of 2026
Dedicated Cameras: Still Superior to Smartphones
by The Ada News
18 hours ago
2 mins read
Picture this: why I think cameras are better than smartphone cameras
The ’90s Magic of Square: 5 Essential RPGs
by Comic Book
18 hours ago
2 mins read
5 Square Games From the 1990s That Still Hold Up Today
Michigan vs. Duke: Must-See Basketball Showdown
by New York Post
21 hours ago
2 mins read
Michigan vs. Duke Basketball: Start Time, Channel, Where To Watch Tonight’s Duke-Michigan Game
Impaired Driver Sparks Deadly I-65 Crash
by The Times Of Northwest Indiana | Breaking News | R
21 hours ago
1 min read
Wrong-way I-65 crash kills one, injures two, Indiana State Police say
Bridging Divides with Faith and Empathy
by Missoulian
1 day ago
2 mins read
Community of Faith: Come together
$44M Hotel Foreclosure Rocks San Antonio River Walk
by San Antonio Report
1 day ago
2 mins read
River Walk hotel goes to public auction after foreclosure notice
Voices Unite Against Merrimack ICE Facility
by Concord Monitor
1 day ago
1 min read
Letter: Agree 100%
Team USA Sets Record with 11th Gold
by Cbs News
1 day ago
1 min read
Team USA captures record-breaking 11th gold medal at Winter Games
Flipping the House: Democrats' Three-Seat Quest
by Norfolk Daily News
1 day ago
2 mins read
Do Democrats even know how to win?
Central Florida Braces for Record Heat Saturday
by Yahoo! News
1 day ago
1 min read
Record-breaking highs expected in Central Florida on Saturday
Indiana Lawmakers Unite on Township Merger
by Shelbynews Com
1 day ago
1 min read
Township merger plan could advance under compromise bill