MAL-2026-17713

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/crates.io/sharpnes/MAL-2026-17713.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17713
Published
2026-10-09T00:00:00Z
Modified
2026-10-09T12:30:05Z
Summary
Malicious code in sharpnes (crates.io)
Details

sharpnes is a malicious crate published to crates.io on 2026-10-09 by the account crows7781-glitch (versions 0.1.0 and 0.1.1), described only as "The sharpnes project is a learn.". It is an infostealer that exfiltrates data to attacker-controlled Telegram bots when the exported async function shortname() is called. src/teleg.rs (commented "telegram stealer") runs on Windows only: it collects Telegram Desktop session data from %USERPROFILE%\AppData\Roaming\Telegram Desktop\tdata and :\Telegram Desktop\tdata (drives C-J), zips it to tdata_backup.zip and uploads it via the Telegram Bot API sendDocument endpoint using a hardcoded bot token to chat -1003869029825. src/data.rs (commented "chrome stealer") uses XOR (key 0xAA) obfuscated strings and Chinese identifiers to locate the Chrome Default profile "Local Extension Settings" directory (which holds browser extension data such as crypto wallet vaults) on Windows, Linux and macOS, zips it in memory and sends it as 文件.zip via teloxide using a second hardcoded bot token to the same chat. In 0.1.0 the Chrome stealer is present but not called; 0.1.1 wires it into shortname().

Database specific
{
    "iocs": {
        "files": [
            {
                "note": "Telegram Desktop tdata stealer (Windows) exfiltrating to Telegram bot 8775554963 / chat -1003869029825.",
                "paths": [
                    "src/teleg.rs"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "note": "XOR (0xAA) obfuscated Chrome 'Local Extension Settings' stealer exfiltrating to Telegram bot 8898886905 / chat -1003869029825.",
                "paths": [
                    "src/data.rs"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "note": "Archive of stolen Telegram Desktop tdata written to the current directory before exfiltration.",
                "paths": [
                    "tdata_backup.zip"
                ],
                "source": "DROPPED"
            }
        ],
        "urls": [
            "https://api.telegram.org/bot8775554963:AAG6n5jLZLDjNo1T9xlMMVn1j2PzwTfn9c0/sendDocument",
            "https://api.telegram.org/bot8898886905:AAFZ4VrHpMvaoYs1XAXpMgm4jbrxhA8wPGI/sendDocument"
        ]
    }
}
References
Credits

Affected packages

crates.io / sharpnes

Package

Name
sharpnes
View open source insights on deps.dev
Purl
pkg:cargo/sharpnes

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/crates.io/sharpnes/MAL-2026-17713.json"