Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Two Malicious Rust Crates Impersonate Popular Logger to Stea...

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
976
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

Malicious Rust crates, "faster_log" and "async_println," were uncovered by Socket's Threat Research Team, impersonating the legitimate "fast_log" library to steal Solana and Ethereum wallet keys by scanning source code for private keys and exfiltrating the data to a command and control (C2) endpoint disguised as a blockchain RPC service. Published by threat actors under the aliases "rustguruman" and "dumbnbased," these crates mimic the original library's functionalities, README, and repository metadata to deceive developers and were downloaded over 8,000 times. The crates perform key exfiltration during application runtime and target Rust toolchains across operating systems. This incident highlights the risks posed by such minimal yet effective supply chain attacks and suggests the need for robust security measures, including secret rotation, file-level scanning, and network egress restrictions. Socket provides several tools, including a GitHub app and CLI, to help detect and prevent the introduction of malicious packages, emphasizing the importance of comprehensive defense strategies to protect development environments.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.