Vulnerability MAL-2026-17713
Summary
Malicious code in sharpnes (crates.io)
Details
sharpnes is a malicious crate published to crates.io on 2026-10-09 by the account crows7781-glitch (versions 0.1.0 and 0.1.1), described only as "The sharpnes project is a learn.". It is an infostealer that exfiltrates data to attacker-controlled Telegram bots when the exported async function shortname() is called. src/teleg.rs (commented "telegram stealer") runs on Windows only: it collects Telegram Desktop session data from %USERPROFILE%\AppData\Roaming\Telegram Desktop\tdata and :\Telegram Desktop\tdata (drives C-J), zips it to tdata_backup.zip and uploads it via the Telegram Bot API sendDocument endpoint using a hardcoded bot token to chat -1003869029825. src/data.rs (commented "chrome stealer") uses XOR (key 0xAA) obfuscated strings and Chinese identifiers to locate the Chrome Default profile "Local Extension Settings" directory (which holds browser extension data such as crypto wallet vaults) on Windows, Linux and macOS, zips it in memory and sends it as 文件.zip via teloxide using a second hardcoded bot token to the same chat. In 0.1.0 the Chrome stealer is present but not called; 0.1.1 wires it into shortname().