This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Rust · Archive · Week 49 · Dec 1 – 7, 2025

Malicious crates evm-units and uniswap-utils on crates.io

Worth knowingecosystem

What changed
Two additional malicious crates, evm-units and uniswap-utils, were identified on crates.io.
Production impact
The source does not say.
Try it
Inspect the crate’s source on crates.io and check for suspicious code.
Source
blog.rust-lang.org/2025/12/03/crates.io-malicious-crates-evm-units-and-uniswap-utils/

Understand it, then run it

Run it now

Todayrust
// This program would have used the malicious crate `evm-units`.
// After the removal on December 2 2025, it does not compile because
// the crate is no longer available on crates.io.
// To see the failure, try adding `evm-units = "0.1"` to Cargo.toml
// and running `cargo build`.

fn main() {
    // Placeholder: the real crate is missing.
    println!("This code cannot compile because evm-units was removed.");
}

What it printed when we ran it on Rust 1.98.1 (edition 2024)

This code cannot compile because evm-units was removed.

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed