Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed

Cybersecurity researchers have uncovered two malicious Rust crates that mimic a trusted library, ultimately stealing Solana and Ethereum wallet keys. With a total of 8,424 downloads, these crates underscore the growing threat to open-source software supply chains.

Key Takeaways:

  • Two crates, faster_log and async_println, impersonate a legitimate library.
  • Cybercriminals targeted Solana and Ethereum wallet keys.
  • The malicious crates were collectively downloaded 8,424 times.
  • They were published on May 25, 2025, by aliases “rustguruman” and “dumbnbased.”
  • This incident highlights the software supply chain’s vulnerability.

The Discovery

Cybersecurity researchers recently identified two malicious Rust crates that disguise themselves as a legitimate library. Known as faster_log and async_println, these crates first caught attention when they appeared suspiciously similar to the established fast_log library. The threat actors behind this scheme, operating under the aliases “rustguruman” and “dumbnbased,” published their crates on May 25, 2025.

The Malicious Method

Instead of offering the same logging functionalities as the authentic fast_log library, these impostor crates incorporated code designed to steal cryptocurrency wallet keys. Solana and Ethereum keys were specifically targeted, exposing unsuspecting developers—and potentially their users—to significant risk. This deceptive approach underscores the importance of scrutinizing dependencies and packages before integrating them into projects.

Impact and Download Figures

According to researchers, the faster_log and async_println crates were collectively downloaded 8,424 times. Such download numbers point to possible widespread exposure among developers who may unknowingly incorporate these dangerous crates into their codebases. In a realm where digital assets and projects require frequent updates, new vulnerabilities can spread rapidly.

Actor’s Aliases and Publication Timeline

Appearing under the aliases “rustguruman” and “dumbnbased,” these malicious actors took advantage of open-source ecosystems’ trust-based model. The crates’ release on May 25, 2025, underscores how quickly threats can disseminate once malicious code is added to a package repository.

Broader Security Implications

This incident signals a larger issue within software development communities. As open-source repositories grow, verifying publisher credibility and analyzing code thoroughly become ever more crucial. Attacks like this illustrate how malicious actors can target the supply chain, putting both developers and end-users at risk.

Next Steps

Such attacks remind us that due diligence is key to securing projects. Developers should carefully vet any library or package they incorporate, monitor for unusual activities, and keep an eye on security advisories. Only through vigilance can the open-source community preserve the integrity and safety of its software repositories.

More from World

Reese vs. Brink: High-Stakes Basketball Drama
by Yardbarker
5 days ago
2 mins read
‘Visibly Emotional’ Angel Reese Caught on Camera as Cameron Brink Shuts Down Dream Star
India's Bold Recycling Shift: From Goals to Action
by Plasticsnews
5 days ago
2 mins read
India’s plastics recycling market must now turn targets into results
Taiwan Charges Nine Over Illegal AI Exports
by Owensboro Messenger And Inquirer
6 days ago
2 mins read
Taiwan charges 9 over illegal AI server exports to China
Deadly Ambush in South Sudan Kills Peacekeepers
by Owensboro Messenger And Inquirer
6 days ago
1 min read
Armed men ambush a patrol in South Sudan and kill 2 UN peacekeepers
West Virginia Schools Face $2.8M Flood Costs
by Wv News
6 days ago
1 min read
Lewis County Board of Education reviews flood cleanup costs: $2.8 million so far
Surfer Airlifted After California Crash
by New York Post
6 days ago
1 min read
Top surfer and his wife in mangled car crash in California
Explicit Imagery Shocks California Classroom
by New York Post
6 days ago
2 mins read
Outrage as school shows kids as young as 14 extremely graphic abortion, sex and transgender art
PGA Tour's Ever-Changing Season Finale
by The Daily News
6 days ago
2 mins read
End of PGA season still a complex work in progress
Darkman's Enduring Impact: 36 Years On
by Comic Book
6 days ago
2 mins read
After 36 Years, This Is Still Sam Raimi’s Best Superhero Movie & I Can Explain Why
Three Wars, One Indomitable Idaho Veteran
by Postregister
6 days ago
2 mins read
Three wars, seven medals, one 97-year-old Idaho veteran still full of life — and the VFW is honoring him for a lifetime of service
Gregory Rodrigues Eyes Middleweight Title Shot
by Mma Fighting
6 days ago
2 mins read
On To the Next One: Matches to make after UFC Sacramento
Kindness Drives: Donate Blood in Central NY
by Romesentinel
6 days ago
1 min read
Red Cross lists September blood drives across Central New York