Two Malicious Rust Crates Impersonate Popular Logger to Stea...
Blog post from Socket
Malicious Rust crates, "faster_log" and "async_println," were uncovered by Socket's Threat Research Team, impersonating the legitimate "fast_log" library to steal Solana and Ethereum wallet keys by scanning source code for private keys and exfiltrating the data to a command and control (C2) endpoint disguised as a blockchain RPC service. Published by threat actors under the aliases "rustguruman" and "dumbnbased," these crates mimic the original library's functionalities, README, and repository metadata to deceive developers and were downloaded over 8,000 times. The crates perform key exfiltration during application runtime and target Rust toolchains across operating systems. This incident highlights the risks posed by such minimal yet effective supply chain attacks and suggests the need for robust security measures, including secret rotation, file-level scanning, and network egress restrictions. Socket provides several tools, including a GitHub app and CLI, to help detect and prevent the introduction of malicious packages, emphasizing the importance of comprehensive defense strategies to protect development environments.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.