Windows, macOS, and Linux systems could be compromised with tailored payloads by the illicit Rust package "evm-units," which impersonates an Ethereum Virtual Machine unit helper tool and has been downloaded more than 7,400 times since April, The Hacker News reports.Uploaded to crates.io by user "ablerust," evm-units monitors for a process related to Chinese security vendor Qihoo 360's 360 Total Security antivirus software before retrieving operating system-specific payloads, according to findings from the Socket Threat Research Team. Absence of the process prompts the creation of a Visual Basic Script wrapper with a concealed PowerShell script."This focus on Qihoo 360 is a rare, explicit, China-focused targeting indicator, because it is a leading Chinese internet company. It fits the crypto-theft profile, as Asia is one of the largest global markets for retail cryptocurrency activity," said Socket researcher Olivia Brown, who also noted the Rust package's integration into the popular uniswap-utils package to enable automated execution.
Threat Intelligence, Malware
OS-specific payloads deployed by nefarious EVM tool-spoofing Rust package

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



