BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

TrapDoor Malware Targets npm, PyPI, Crates.io in Supply Chain Attack

TrapDoor malware campaign steals crypto secrets via npm, PyPI, Crates.io packages.

  • A coordinated supply chain attack, codenamed TrapDoor, has deployed malware across three major developer platforms: npm, PyPI, and Crates.io.
  • The campaign targets crypto, DeFi, Solana, and AI developers to steal credentials, wallets, and secrets via malicious packages.
  • Attackers use sophisticated persistence methods, including AI assistant trickery via hidden files, to maintain access and move laterally.
  • Over 34 malicious packages across 384 versions have been identified, with the earliest activity recorded on May 22, 2026.

A sophisticated new malware campaign has targeted developers across three major software ecosystems, according to a recent report. The coordinated attack, dubbed TrapDoor, began distributing credential-stealing packages on May 22, 2026, via npm, PyPI, and Crates.io.

- Advertisement -

Consequently, the malicious operation spans more than 34 packages across over 384 versions. The packages are designed to masquerade as legitimate developer tools for crypto and AI workflows.

These malicious modules specifically target developers in crypto, DeFi, Solana, and AI communities. Their primary goal is to steal developer secrets, cryptocurrency wallets, SSH keys, and cloud credentials.

Several npm packages deploy a shared payload called trap-core.js. This script scans for credentials, validates stolen AWS and GitHub tokens, and plants persistence mechanisms.

The campaign also uses a clever technique to exploit AI coding assistants. It implants hidden instructions in project files like .cursorrules and CLAUDE.md to trigger malicious actions.

- Advertisement -

Meanwhile, the Rust crates search for local keystores and exfiltrate encrypted data to GitHub Gists. They leverage build scripts to execute malicious code upon installation.

Similarly, the Python packages auto-execute on import to download remote JavaScript payloads. This method allows attackers to update the malware’s behavior without republishing packages.

The complete list of identified packages reveals names tailored to appear relevant to crypto development and security. This typosquatting strategy aims to reach a broad audience of unsuspecting developers.

The operation demonstrates how attackers are combining traditional methods with newer developer-environment attack paths. “TrapDoor shows how attackers are combining traditional package typosquatting with newer developer-environment attack paths,” Socket said.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Mining Mogul Chun Wang Purchases SpaceX Mars Mission

Chun Wang, founder of the Bitcoin mining pool F2Pool, has purchased and will join...

$1,000 in SHIB Could’ve Become $99.1 Million

A $1,000 investment in Shiba Inu on its all-time low day in November 2020...

BitMEX Analyst: Bond Yield Surge Fuels Bitcoin Supercycle

A Bitmex analyst argues surging sovereign bond yields will force a "structural" shift, creating...

U.S. Lawmakers Push “Fort Knox” Bitcoin Reserve Plan

The ARMA Act proposes creating a U.S. Strategic Bitcoin Reserve, backed by 5% of...

The Secret Behind Shiba Inu’s Meteoric 2021 Rise

Shiba Inu's 2021 rally was fueled by a massive token burn by Ethereum co-founder...

Must Read

26 Best Investment Audiobooks on Audible

Looking to expand your financial knowledge? Me too..When I first started investing, I was completely lost. There were so many terms, strategies, and theories...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading