The crates.​io team was notified of two malicious crates (with similar names as legitimate crates) which were actively searching file contents for Etherum private keys, Solana private keys, and arbitrary byte arrays for exfiltration. The malicious crates have been removed.

See the blog post for details: blog.rust-lang.org/2025/09/24/

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://social.rust-lang.org/users/rust/statuses/115261259717707928 on your instance and quote it. (Note that quoting is not supported in Mastodon.)