Post
Topic
Board Beginners & Help
Re: Malware-laced Rust packages on Crates.io stealing crypto wallets
by
joniboini
on 27/09/2025, 16:19:35 UTC
If a website does kotnhave the signature, there is no way you can know that the file on the site to download has not been replaced by hackers.
True. I wonder if we have a website or database where users submit a hash of a file manually as a way to cross-check download files. I know the responsibility should lie with the company to provide that stuff, especially with the possibility of scammers uploading misleading hash. I'm just curious if someone has built a tool like that. Another option is to use malware scanner to check them I guess (other than making sure you visit the right website, double checking on social media, etc).