Vulnerability MAL-2026-17713

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
16 hours ago
October 09, 2026 at 12:00 AM UTC
Malicious code in sharpnes (crates.io)
0.1.0 - 0.1.5
0.1.0 - 0.1.5

Summary

Malicious code in sharpnes (crates.io)

Details

sharpnes is a malicious crate published to crates.io on 2026-10-09 by the account crows7781-glitch (versions 0.1.0 and 0.1.1), described only as "The sharpnes project is a learn.". It is an infostealer that exfiltrates data to attacker-controlled Telegram bots when the exported async function shortname() is called. src/teleg.rs (commented "telegram stealer") runs on Windows only: it collects Telegram Desktop session data from %USERPROFILE%\AppData\Roaming\Telegram Desktop\tdata and :\Telegram Desktop\tdata (drives C-J), zips it to tdata_backup.zip and uploads it via the Telegram Bot API sendDocument endpoint using a hardcoded bot token to chat -1003869029825. src/data.rs (commented "chrome stealer") uses XOR (key 0xAA) obfuscated strings and Chinese identifiers to locate the Chrome Default profile "Local Extension Settings" directory (which holds browser extension data such as crypto wallet vaults) on Windows, Linux and macOS, zips it in memory and sends it as 文件.zip via teloxide using a second hardcoded bot token to the same chat. In 0.1.0 the Chrome stealer is present but not called; 0.1.1 wires it into shortname().

Impacted packages

Timeline

Published
16 hours ago
October 09, 2026 at 12:00 AM UTC
Last Modified
3 hours ago
October 09, 2026 at 12:30 PM UTC