Two malicious Rust packages, named 'faster_log' and 'async_println', were discovered on the official Crates.io repository, where they were designed to steal private keys from cryptocurrency wallets, specifically targeting Solana and Ethereum users. These packages were downloaded nearly 8,500 times before their removal, with 'faster_log' accounting for 7,200 downloads and 'async_println' for 1,200. The malicious crates impersonated the legitimate 'fast_log' crate by copying its README file, repository metadata, and maintaining the original logging functionality to avoid suspicion among developers. The attackers embedded a payload within the crates that, upon execution, scanned the victim's environment and project source files for sensitive information, including hex strings resembling Ethereum private keys, Base58 strings similar to Solana keys or addresses, and bracketed byte arrays that could contain keys or seeds. When such data was found, it was bundled with the file path and line number and exfiltrated to a hardcoded Cloudflare Worker URL, which was confirmed to be live and accepting POST requests during the investigation. The malicious activity was discovered by researchers at the code security company Socket, who promptly reported it to Crates.io. In response, Crates.io removed both packages and suspended the publishing accounts, 'rustguruman' and 'dumbnbased', on September 24th. The incident highlights the risks associated with open-source software supply chains, where attackers can leverage trusted repositories to distribute malware to unsuspecting developers. The malicious crates did not have any dependent downstream crates, which may have limited the spread of the compromise. The attack demonstrates the sophistication of threat actors in mimicking legitimate projects to evade detection and the importance of vigilant monitoring of package repositories. The use of a legitimate logging functionality within the malicious crates further reduced suspicion, allowing the packages to remain undetected for several months. The exfiltration endpoint used by the attackers was not an official Solana RPC endpoint, indicating a deliberate attempt to disguise the data theft operation. This supply chain attack underscores the need for developers to verify the authenticity of third-party packages and for repository maintainers to implement robust security controls. The incident also serves as a warning to the broader cryptocurrency and developer communities about the ongoing threat of targeted attacks seeking to compromise digital assets through software dependencies. Security researchers continue to monitor for similar threats and advise immediate removal of the affected packages from any projects.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers and security outlets disclosed that the malicious Rust crates on Crates.io were stealing crypto wallet keys, bringing public attention to the supply-chain attack. Reporting identified the campaign as targeting Solana and Ethereum private keys through trojanized packages.
A set of malicious Rust packages was published on Crates.io as part of a supply-chain attack aimed at stealing cryptocurrency wallet private keys. The packages targeted Solana and Ethereum-related secrets and were designed to exfiltrate sensitive key material from developers or users who installed them.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.