TLDR Security firm Socket discovered a malware campaign called “TrapDoor” deploying 34 malicious packages across npm, PyPI, and Crates developer ecosystems TheTLDR Security firm Socket discovered a malware campaign called “TrapDoor” deploying 34 malicious packages across npm, PyPI, and Crates developer ecosystems The

TrapDoor Malware Targets Crypto and AI Developers in Supply Chain Attack

2026/05/25 15:35
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

TLDR

  • Security firm Socket discovered a malware campaign called “TrapDoor” deploying 34 malicious packages across npm, PyPI, and Crates developer ecosystems
  • The attack targets crypto, DeFi, AI, and security developers to steal wallet data, SSH keys, cloud credentials, and API keys
  • TrapDoor targets major crypto wallets including Coinbase, Binance, Solana, MetaMask, and the Brave browser
  • The malware injects hidden instructions to hijack AI coding assistants Claude and Cursor, tricking them into running fake “security scans”
  • GitHub, which was used to spread the packages, had itself been compromised on May 20 after an employee’s device was breached

Developers building crypto and AI tools are being targeted by a new malware campaign that hides inside software packages they routinely download as part of their work.

Security firm Socket published a report on Sunday revealing the campaign, which it named “TrapDoor.” Socket said it discovered the attack on Friday. By the time of the report, attackers had already pushed more than 34 malicious packages and 384 related versions across multiple developer ecosystems.

TrapDoor Malware Targets Crypto and AI Developers in Supply Chain Attack

What TrapDoor Does

The malware is designed to steal sensitive data. Targets include crypto wallet information, SSH keys, cloud credentials, GitHub tokens, browser extension data, and API keys.

Socket’s chief technology officer Ahmad Nassri confirmed the malware goes after several major crypto wallets. Those include Coinbase, Binance, Solana, Sui, Aptos, and MetaMask. The Brave browser is also a target.

One aspect of TrapDoor makes it stand out. The malware injects hidden instructions into AI coding assistants, specifically Claude and Cursor. It tricks these tools into running what appears to be a security scan, which then causes the assistant to find and send out sensitive data without the developer realizing.

The malicious packages were found in three major developer repositories. These are npm, used by JavaScript and Node.js developers; PyPI, widely used in data science, AI, and automation; and Crates, used by Rust developers.

How the Attack Works

The package names were made to look like normal developer tools. Socket said they were designed to resemble development helpers, project setup tools, model routing utilities, and build helpers for Solidity, Sui, and Move.

This approach gives the campaign access to a wide range of developers who work with crypto wallets, cloud services, and GitHub on a regular basis.

Socket said the attack showed signs of being AI-assisted. The GitHub activity included broad security-themed scaffolding, generic lure repositories, and prompt-injection documentation mixed with working malware components.

GitHub was used to spread the malicious packages. The platform had already reported a separate security incident on May 20, when unauthorized access to its internal repositories was discovered following the compromise of an employee’s device.

Socket noted the median detection time for malicious versions was 5 minutes and 27 seconds. The fastest detection came just 58 seconds after a package was released.

The attack is part of a wider trend of threat actors loading poisoned packages into developer repositories, knowing developers will install them as part of routine workflows, often without close inspection.

Socket has not named any specific individuals or groups behind TrapDoor. The campaign was still active at the time of reporting.

The post TrapDoor Malware Targets Crypto and AI Developers in Supply Chain Attack appeared first on CoinCentral.

Market Opportunity
Gensyn Logo
Gensyn Price(AI)
$0.03136
$0.03136$0.03136
-1.93%
USD
Gensyn (AI) Live Price Chart

AI Strategy: Powered 24/7

AI Strategy: Powered 24/7AI Strategy: Powered 24/7

Generate automated strategies using natural language

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Crypto selloff deepens with $400 million liquidations and rising short interest

Crypto selloff deepens with $400 million liquidations and rising short interest

The post Crypto selloff deepens with $400 million liquidations and rising short interest appeared on BitcoinEthereumNews.com. Bitcoin BTC$66,444.55 gave back a
Share
BitcoinEthereumNews2026/04/02 19:02
Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Share
BitcoinEthereumNews2025/09/18 00:36
Gold Spot Volume on Binance Surges to $80M as Demand Extends Beyond Futures

Gold Spot Volume on Binance Surges to $80M as Demand Extends Beyond Futures

TLDR: Gold spot trading on Binance reached nearly $80M shortly after launch, showing rapid market adoption. Despite a 15% correction, gold continues attracting
Share
Blockonomi2026/04/02 18:18

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!