Malicious Rust Evm-Units Mimic as EVM Version Silently Executes OS-specific Payloads

The open-source software supply chain recently encountered a deceptive threat in the form of evm-units, a malicious Rust crate published by the author ablerust. Masquerading as a standard utility for verifying Ethereum Virtual Machine (EVM) versions, the package accumulated thousands of downloads before it was removed. While the library appeared to perform legitimate version checks, […]

The post Malicious Rust Evm-Units Mimic as EVM Version Silently Executes OS-specific Payloads appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: