TrapDoor Supply-Chain Attack Hits 34 Packages on npm, PyPI, Crates.io, Targets Aptos, Sui and Solana Developers
Security firm Socket identified TrapDoor, a supply-chain malware campaign spanning 34 malicious packages and 384 versions and artifacts across npm, PyPI and Crates.io, targeting developer environments for Aptos, Sui and Solana and, more broadly, crypto, DeFi, AI and security developers. The malware is designed to steal wallets, SSH keys, cloud credentials, GitHub tokens, browser data, environment variables and API keys, and researchers said attackers kept pushing new releases across the registries.
Researchers also linked the operation to GitHub activity, including pull requests that try to add .cursorrules and CLAUDE.md files to popular repositories. Those hidden instruction files can be read by AI coding assistants such as Claude and Cursor when developers clone a project, showing the campaign is trying to compromise developers through repositories as well as package managers.
From the sources (14 posts)
@rez0__RT @inf0stache: After seeing the same account submit PRs to MCP related repos, I figured I'd write up what I've found so far. Hidden READM…
@rez0__Quote tweet is prompt injection attacks in the wild. This is the first REAL one I’ve seen. And it’s using GitHub issues which is the main way/channel that gets tested these days. (In my testing for OpenAI and Google products).
@socketsecurity🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.io. Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases acros
@socketsecurityMore analysis, package details, IOCs, and GitHub-related activity here, including attacker-hosted payload/config infrastructure and PRs attempting to add .cursorrules / CLAUDE.md files to popular AI and developer projects:
@darkwebinformerHere we go again...
@socketsecurity@adnanthekhan Fair - intentionally published malware isn’t new. The reason we treated this as active/breaking is that the campaign is still moving: more artifacts getting pushed and tagged across the registries while tracking it, alongside
@intcyberdigest
@kimmonismusA coordinated supply chain attack called "TrapDoor" just hit npm, PyPI, and Crates. io simultaneously, 34 malicious packages targeting crypto, AI, and security developers to steal wallets, SSH keys, and cloud credentials. New: attackers ar
@coindeskALERT: Security researchers identify a malware campaign dubbed "TrapDoor" targeting crypto developer environments for @Aptos, @SuiNetwork and @Solana via 34+ malicious packages designed to steal SSH keys and wallet credentials. https://t.co
@laurashinRT @CoinDesk: ALERT: Security researchers identify a malware campaign dubbed "TrapDoor" targeting crypto developer environments for @Aptos,…
@wesrothA major supply chain attack is actively targeting npm, PyPI, and through a crypto-stealing campaign called TrapDoor. TrapDoor has hit 34 malicious packages across 384 versions and artifacts, with attackers repeatedl
@theblockcoResearchers flag TrapDoor malware campaign targeting crypto developer environments including Aptos, Sui and Solana
@theblockcoRT @DangaWrites: 🚨@SocketSecurity identified TrapDoor malware campaign spanning 34+ malicious packages and 384+ versions across npm, PyPI,…
@cointelegraph🚨 ALERT: TrapDoor malware is targeting crypto and AI developers via a supply chain attack, deploying 34 malicious packages to steal wallets, SSH keys, and API keys. The malware also injects hidden instructions to hijack AI coding assistan