Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed

Cybersecurity researchers have uncovered two malicious Rust crates that mimic a trusted library, ultimately stealing Solana and Ethereum wallet keys. With a total of 8,424 downloads, these crates underscore the growing threat to open-source software supply chains.

Key Takeaways:

  • Two crates, faster_log and async_println, impersonate a legitimate library.
  • Cybercriminals targeted Solana and Ethereum wallet keys.
  • The malicious crates were collectively downloaded 8,424 times.
  • They were published on May 25, 2025, by aliases “rustguruman” and “dumbnbased.”
  • This incident highlights the software supply chain’s vulnerability.

The Discovery

Cybersecurity researchers recently identified two malicious Rust crates that disguise themselves as a legitimate library. Known as faster_log and async_println, these crates first caught attention when they appeared suspiciously similar to the established fast_log library. The threat actors behind this scheme, operating under the aliases “rustguruman” and “dumbnbased,” published their crates on May 25, 2025.

The Malicious Method

Instead of offering the same logging functionalities as the authentic fast_log library, these impostor crates incorporated code designed to steal cryptocurrency wallet keys. Solana and Ethereum keys were specifically targeted, exposing unsuspecting developers—and potentially their users—to significant risk. This deceptive approach underscores the importance of scrutinizing dependencies and packages before integrating them into projects.

Impact and Download Figures

According to researchers, the faster_log and async_println crates were collectively downloaded 8,424 times. Such download numbers point to possible widespread exposure among developers who may unknowingly incorporate these dangerous crates into their codebases. In a realm where digital assets and projects require frequent updates, new vulnerabilities can spread rapidly.

Actor’s Aliases and Publication Timeline

Appearing under the aliases “rustguruman” and “dumbnbased,” these malicious actors took advantage of open-source ecosystems’ trust-based model. The crates’ release on May 25, 2025, underscores how quickly threats can disseminate once malicious code is added to a package repository.

Broader Security Implications

This incident signals a larger issue within software development communities. As open-source repositories grow, verifying publisher credibility and analyzing code thoroughly become ever more crucial. Attacks like this illustrate how malicious actors can target the supply chain, putting both developers and end-users at risk.

Next Steps

Such attacks remind us that due diligence is key to securing projects. Developers should carefully vet any library or package they incorporate, monitor for unusual activities, and keep an eye on security advisories. Only through vigilance can the open-source community preserve the integrity and safety of its software repositories.

More from World

Iran's Unbreakable Leadership Chain
by The New York Sun
2 months ago
1 min read
Bombed, Beheaded, But Not Broken: Why Iran’s Regime Hasn’t Splintered
PennDOT's 2026 Kicks Off with Liberty Street Focus
by Thederrick
2 months ago
1 min read
PennDOT discusses public safety, minimal disruption, city-state teamwork regarding Liberty Street project
Cape Girardeau’s Decades of April 10 Milestones
by Semissourian
2 months ago
2 mins read
Out of the past: April 10
Big Savings on Organic Bedding by Naturepedic
by Wired
2 months ago
1 min read
Naturepedic Promo Codes and Deals: 20% Off
Ballot Battle: Signatures Disputed in Prescott Race
by Prescott Daily Courier
2 months ago
1 min read
Lawsuit over petition signatures could decide race for Justice of the Peace
Betting on Blockchain: Spartans Casino’s $7M Leap
by Analytics And Insight
2 months ago
2 mins read
Real-Time Stakes: Spartans Casino Uses Blockchain to Power its $7,000,000 Leaderboard
Safeguarding Iowa: Protection Bill Awaits Governor
by The Quad City Times
2 months ago
1 min read
Capitol Notebook: Iowa bill strengthening safety measures for judges, legislators goes to governor
Texas A&M Launches $200M Chip Institute
by Communityimpact
2 months ago
2 mins read
Abbott calls for ‘microchip independence’ at Texas A&M Semiconductor Institute groundbreaking
A Guilty Plea at Gilgo Beach
by Riverhead News Review
2 months ago
2 mins read
Gilgo Beach killer Rex Heuermann guilty plea brings closure to victims’ families
Write-In Campaign Shakes GOP Primary
by Indianagazette
2 months ago
2 mins read
Mastriano supporters start write-in bid for state senator in May primary
Connection Over Punishment: UNM's Restorative Vision
by Unm Ucam Newsroom
2 months ago
2 mins read
When punishment fails, connection leads: UNM educator earns national recognition for restorative work
Clemson Targets Quinnipiac's 6'9" Forward
by Si
2 months ago
2 mins read
Clemson head coach Brad Brownell and the Tigers are in touch with Quinniapiac forward Grant Randall.