Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed

Cybersecurity researchers have uncovered two malicious Rust crates that mimic a trusted library, ultimately stealing Solana and Ethereum wallet keys. With a total of 8,424 downloads, these crates underscore the growing threat to open-source software supply chains.

Key Takeaways:

  • Two crates, faster_log and async_println, impersonate a legitimate library.
  • Cybercriminals targeted Solana and Ethereum wallet keys.
  • The malicious crates were collectively downloaded 8,424 times.
  • They were published on May 25, 2025, by aliases “rustguruman” and “dumbnbased.”
  • This incident highlights the software supply chain’s vulnerability.

The Discovery

Cybersecurity researchers recently identified two malicious Rust crates that disguise themselves as a legitimate library. Known as faster_log and async_println, these crates first caught attention when they appeared suspiciously similar to the established fast_log library. The threat actors behind this scheme, operating under the aliases “rustguruman” and “dumbnbased,” published their crates on May 25, 2025.

The Malicious Method

Instead of offering the same logging functionalities as the authentic fast_log library, these impostor crates incorporated code designed to steal cryptocurrency wallet keys. Solana and Ethereum keys were specifically targeted, exposing unsuspecting developers—and potentially their users—to significant risk. This deceptive approach underscores the importance of scrutinizing dependencies and packages before integrating them into projects.

Impact and Download Figures

According to researchers, the faster_log and async_println crates were collectively downloaded 8,424 times. Such download numbers point to possible widespread exposure among developers who may unknowingly incorporate these dangerous crates into their codebases. In a realm where digital assets and projects require frequent updates, new vulnerabilities can spread rapidly.

Actor’s Aliases and Publication Timeline

Appearing under the aliases “rustguruman” and “dumbnbased,” these malicious actors took advantage of open-source ecosystems’ trust-based model. The crates’ release on May 25, 2025, underscores how quickly threats can disseminate once malicious code is added to a package repository.

Broader Security Implications

This incident signals a larger issue within software development communities. As open-source repositories grow, verifying publisher credibility and analyzing code thoroughly become ever more crucial. Attacks like this illustrate how malicious actors can target the supply chain, putting both developers and end-users at risk.

Next Steps

Such attacks remind us that due diligence is key to securing projects. Developers should carefully vet any library or package they incorporate, monitor for unusual activities, and keep an eye on security advisories. Only through vigilance can the open-source community preserve the integrity and safety of its software repositories.

More from World

Trump Criticizes Al Sharpton in New Feud
by The Mirror Us
17 hours ago
2 mins read
Trump mocks civil rights activist Rev. Al Sharpton with ‘shameful’ post
Camair-Co Expands Fleet, Boosts Cameroon Connectivity
by Travel And Tour World
17 hours ago
2 mins read
New Aircraft, New Adventures: Camair-Co’s Boeing 737-800 Elevates Cameroon’s Travel Experience
PEPE's Surge Outpaces Bitcoin Amid Crypto Boom
by Biztoc
17 hours ago
2 mins read
PEPE Outpaces Bitcoin, XRP After 3% Spike, Analyst Draws Parallels With Earlier 1000% Rally, Calls Price Action ‘Insane’
EU Proposes Travel Limits for Russian Diplomats
by Biztoc
17 hours ago
1 min read
EU looking to impose travel curbs on Russian diplomats
Chourio, Brewers Unstoppable in 7-3 Win
by Yardbarker
17 hours ago
1 min read
Chourio Delivers Clutch Blast As Brewers Dominate Cubs To Seize Commanding NLDS Lead
Airbus Transforms Manufacturing with 5G Connectivity
by Computerweekly News
17 hours ago
2 mins read
Airbus climbs in industrial digitisation with private 5G deployment
Chicago Volleyball Rankings See Exciting Shifts
by Chicago Tribune
18 hours ago
1 min read
Jeff Vorva’s high school girls volleyball rankings and player of the week for the Daily Southtown
Jaguars' Win: Triumph, Flaws, and Future Focus
by Yahoo! News
18 hours ago
2 mins read
Good, bad and ugly from Jaguars’ Week 5 win vs. the Chiefs
Barcelona Airport Hit by Seven Flight Cancellations
by Travel And Tour World
19 hours ago
2 mins read
Barcelona Airport Sees Travel Disruptions as Seven New Flights Get Canceled by Lufthansa, EasyJet, American Airlines, Volotea, and More Impacting Routes to Buenos Aires, Philadelphia, Munich, Bristol, Florence, and Milan
Detroit Dominates Memphis in 128-112 Victory
by 12news
19 hours ago
2 mins read
Detroit 128, Memphis 112
Arson Arrest Shakes Denton County Community
by Wfaa
19 hours ago
1 min read
Woman arrested for arson in Denton County fire that destroyed 3 homes
MAGA Movement Amplifies Political Deception
by Daily Freeman
20 hours ago
2 mins read
Dick Polman: MAGA has perfected the unrepentant lie