---
id: MAL-2026-17713
title: Malicious code in sharpnes (crates.io)
summary: Malicious code in sharpnes (crates.io)
severity: critical
exploited: true
vendor: sharpnes
product: sharpnes
ecosystem: rust
affected:
  - sharpnes
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T12:30:05.055843192Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-17713'
references:
  - url: 'https://crates.io/crates/sharpnes'
  - url: 'https://github.com/crows7781-glitch/shortneer'
tags:
  - osv
  - rust
  - malware
ingestedAt: '2026-10-10T07:37:42.967Z'
---

## Overview

sharpnes is a malicious crate published to crates.io on 2026-10-09 by the account crows7781-glitch (versions 0.1.0 and 0.1.1), described only as "The sharpnes project is a learn.". It is an infostealer that exfiltrates data to attacker-controlled Telegram bots when the exported async function shortname() is called. src/teleg.rs (commented "telegram stealer") runs on Windows only: it collects Telegram Desktop session data from %USERPROFILE%\AppData\Roaming\Telegram Desktop\tdata and <drive>:\Telegram Desktop\tdata (drives C-J), zips it to tdata_backup.zip and uploads it via the Telegram Bot API sendDocument endpoint using a hardcoded bot token to chat -1003869029825. src/data.rs (commented "chrome stealer") uses XOR (key 0xAA) obfuscated strings and Chinese identifiers to locate the Chrome Default profile "Local Extension Settings" directory (which holds browser extension data such as crypto wallet vaults) on Windows, Linux and macOS, zips it in memory and sends it as 文件.zip via teloxide using a second hardcoded bot token to the same chat. In 0.1.0 the Chrome stealer is present but not called; 0.1.1 wires it into shortname().

## Affected packages

- `sharpnes`

## Remediation

Refer to the advisory for the patched release.
