fromThe Hacker News
1 week agoMalicious Rust Crate Delivers OS-Specific Malware to Web3 Developer Systems
"Based on the victim's operating system and whether Qihoo 360 antivirus is running, the package downloads a payload, writes it to the system temp directory, and silently executes it," Socket security researcher Olivia Brown said in a report. "The package appears to return the Ethereum version number, so the victim is none the wiser." A notable aspect of the package is that it is explicitly designed to check for the presence of the "qhsafetray.exe" process,
Information security










.jpg?width=1200&height=630&fit=crop&enable=upscale&auto=webp)
