Key Takeaways
A massive cross-platform software supply chain attack targeting crypto and AI developers has exposed how malicious packages hidden inside popular open-source ecosystems can silently steal wallets, cloud credentials, and sensitive developer secrets.
Security researchers at Socket uncovered an active malware campaign dubbed “TrapDoor,” which spread across npm, PyPI, and Crates.io using dozens of fake developer tools disguised as security scanners, Solidity helpers, AI utilities, and blockchain development packages.
According to Socket, the operation involved at least 34 malicious packages and hundreds of related versions and artifacts published across the three major software registries.
The malware targeted developers working in crypto, DeFi, Solana, Sui, AI, and cloud infrastructure environments.
The campaign is especially alarming because it combines traditional package-based malware with newer AI-focused attack techniques designed to manipulate developer assistants such as Claude and Cursor.
+245
Ethereum
Tether
Build'N'Build
USD Coin
Solana
Ripple
Dogecoin
Cardano
Toncoin
Shiba Inu
Avalanche
TRON
Chainlink
Polygon Matic
Polkadot
Wrapped Bitcoin
Litecoin
Dai
NEAR Protocol
Bitcoin Cash
Monero
Stellar
Cosmos
Filecoin
Ethereum Classic
Aptos
Hedera Hashgraph
Immutable
Optimism
Arbitrum
VeChain
The Sandbox
Decentraland
Axie Infinity
Injective Protocol
Render Token
The Graph
Maker
Aave
Chiliz
Helium
PAX Gold
Compound
Lido DAO Token
THORChain
Stacks
Arweave
Sui
Conflux Network
Lido Staked ETH
Bitget Token
Wrapped Ethereum
OKB
Uniswap
Pepe
Ondo
Mantle
First Digital USD
Bittensor
Kaspa
Celestia
XDC Network
Artificial Superintelligence Alliance
Jupiter
Quant
Worldcoin
PayPal USD
Bonk
Rocket Pool ETH
Flare
Tether Gold
Sei
JITO
JasmyCoin
PancakeSwap
Core
Floki Inu
Ethereum Name Service
SushiSwap
Kava.io
1inch Network
Tezos
Algorand
Flow
Trust Wallet Token
Curve DAO Token
KuCoin Token
MultiversX
GateToken
Zcash
IOTA
Basic Attention Token
Enjin Coin
Frax
Ethena
Ethena USDe
Ethena Staked USDe
BlackRock USD Institutional Digital Liquidity Fund
Fasttoken
Pi Network
SATS
Adventure Gold
Audius
Acala Token
Alchemy Pay
Arkham
API3
Bounce Token
Bitcoin
Altlayer
Aergo
Amp
Aevo
ARPA Chain
Astar
Ark
Ankr
AirSwap
Axelar
Alpaca Finance
SingularityNET
Blur
Beam
Badger DAO
Bancor
BakeryToken
Biconomy
Chromia
Tranchess
Celer Network
Celo
Shentu
Civic
Convex Finance
Cartesi
Cyber
COTI
DigiByte
DIA
Dymension
dYdX
ether.fi
FUNToken
FLUX
Firo
Ampleforth Governance Token
Golem
GMX
Gnosis
Gitcoin
Moonbeam
Holo
IoTex
ICON
Illuvium
JUST
Kadena
Kusama
Liquity
Livepeer
Lisk
Memecoin
Manta Network
Treasure
Mask Network
MetisDAO
NKN
Neutron
Ocean Protocol
Origin Protocol
ORDI
Ontology
Osmosis
Powerledger
Phala Network
Pendle
Portal
Pyth Network
ConstitutionDAO
Polkastarter
Qtum
iExec RLC
Rocket Pool
Reserve Rights
Ronin
Ravencoin
Starknet
Storj
Status
Spell Token
Sun (New)
Saga
SuperVerse
Toko Token
Theta Fuel
Tellor
Tensor
Unstoppable Ecosystem Token
Wrapped BNB
LayerZero
Scroll
Usual
Cetus Protocol
Eigenlayer
Hamster Kombat
Catizen
Berachain
KAITO
Pudgy Penguins
Vana
Solayer
Bio Protocol
ChainGPT
Cookie DAO
Solv Protocol
Alchemix
Bitcoin SV
Usual USD
Movement
DeXe
Kelp DAO Restaked ETH
Binance Staked SOL
Nexo
Solv Protocol BTC
Tokenize Xchange
Wrapped eETH
Hyperliquid
Casper
Zilliqa
Secret
Nervos Network
TrueUSD
EOS
BitTorrent
Mina
Dash
STEPN
Gemini Dollar
UNUS SED LEO
Synthetix
Neo
APEcoin
Gala
Theta Network
Fantom
Cronos
Internet Computer
Binance USD
+96
Bitcoin
Ethereum
Tether
Build'N'Build
USD Coin
Solana
Ripple
Dogecoin
Cardano
Toncoin
Shiba Inu
Avalanche
TRON
Chainlink
Polygon Ecosystem Token
Polkadot
Wrapped Bitcoin
Litecoin
Dai
NEAR Protocol
Bitcoin Cash
Monero
Stellar
Cosmos
Filecoin
Ethereum Classic
Aptos
Hedera Hashgraph
Immutable
Optimism
Arbitrum
VeChain
The Sandbox
Decentraland
Axie Infinity
Injective Protocol
Render Token
The Graph
Maker
Aave
Chiliz
Helium
PAX Gold
Compound
Lido DAO Token
THORChain
Stacks
Arweave
Sui
Conflux Network
Lido Staked ETH
Bitget Token
Wrapped Ethereum
OKB
Uniswap
Pepe
Ondo
Mantle
First Digital USD
Bittensor
Kaspa
Celestia
XDC Network
Artificial Superintelligence Alliance
Jupiter
Quant
Worldcoin
PayPal USD
Bonk
Rocket Pool ETH
Flare
Tether Gold
Sei
JITO
JasmyCoin
PancakeSwap
Core
Floki Inu
Ethereum Name Service
SushiSwap
Kava.io
1inch Network
Tezos
Algorand
Flow
Trust Wallet Token
Curve DAO Token
KuCoin Token
MultiversX
GateToken
Zcash
IOTA
Basic Attention Token
Enjin Coin
Frax
Ethena
Ethena USDe
Ethena Staked USDe
BlackRock USD Institutional Digital Liquidity Fund
Fasttoken
Pi Network
+95
Bitcoin
Ethereum
Tether
Build'N'Build
USD Coin
Solana
Ripple
Dogecoin
Cardano
Toncoin
Shiba Inu
Avalanche
TRON
Chainlink
Polygon Ecosystem Token
Polkadot
Wrapped Bitcoin
Litecoin
Dai
NEAR Protocol
Bitcoin Cash
Monero
Cosmos
Filecoin
Ethereum Classic
Aptos
Hedera Hashgraph
Immutable
Optimism
Arbitrum
VeChain
The Sandbox
Decentraland
Axie Infinity
Injective Protocol
Render Token
The Graph
Maker
Aave
Chiliz
Helium
PAX Gold
Compound
Lido DAO Token
THORChain
Stacks
Arweave
Sui
Conflux Network
Lido Staked ETH
Bitget Token
Wrapped Ethereum
OKB
Uniswap
Pepe
Ondo
Mantle
First Digital USD
Bittensor
Kaspa
Celestia
XDC Network
Artificial Superintelligence Alliance
Jupiter
Quant
Worldcoin
PayPal USD
Bonk
Rocket Pool ETH
Flare
Tether Gold
Sei
JITO
JasmyCoin
PancakeSwap
Core
Floki Inu
Ethereum Name Service
SushiSwap
Kava.io
1inch Network
Tezos
Algorand
Flow
Trust Wallet Token
Curve DAO Token
KuCoin Token
MultiversX
GateToken
Zcash
IOTA
Basic Attention Token
Enjin Coin
Frax
Ethena
Ethena USDe
Ethena Staked USDe
BlackRock USD Institutional Digital Liquidity Fund
Fasttoken
Pi Network
Researchers said the earliest known TrapDoor package appeared on PyPI on May 22, 2026, under the name “eth-security-auditor.” From there, the malware rapidly expanded across multiple ecosystems through coordinated publishing waves.
The malicious packages used ecosystem-specific execution methods to compromise victims during normal software installation or build processes.
On npm, packages relied on postinstall hooks to automatically execute malware immediately after installation.
Socket researchers identified more than 20 malicious npm packages with names such as “wallet-security-checker,” “defi-threat-scanner,” and “web3-secrets-detector.”

Once installed, the packages deployed a shared JavaScript payload called “trap-core.js,” a credential-stealing tool spanning more than 1,100 lines of code.
The payload scanned infected systems for:
Researchers said the malware also validated stolen AWS and GitHub credentials through live API calls, helping attackers distinguish valuable accounts from expired or invalid ones.
On PyPI, the malware executed remote JavaScript payloads during Python package imports. Instead of embedding the malicious code directly, the packages downloaded JavaScript from attacker-controlled GitHub Pages infrastructure and executed it using Node.js commands.
Meanwhile, the Rust ecosystem was targeted through malicious Crates.io packages aimed specifically at Sui and Move blockchain developers.
These packages abused Rust’s build.rs functionality, which executes automatically during compilation.
The malicious build scripts searched for wallet keystores, encrypted the data using a hardcoded XOR key, and exfiltrated it to GitHub Gists controlled by the attackers.
One of the most unusual aspects of the TrapDoor campaign was its use of AI-targeted injection techniques.
Researchers found that the malware attempted to manipulate AI coding assistants via hidden instructions embedded in files such as “.cursorrules” and “CLAUDE.md.” These files are commonly used to provide project guidance to AI developer tools.
The attackers used zero-width Unicode characters to hide malicious instructions that tricked AI assistants into performing fake “security scans” that exposed sensitive local credentials and environment data.
Socket said the malware also established multiple persistence mechanisms to maintain access after initial infection. Observed persistence methods included git hooks, shell hooks, systemd services, cron jobs, SSH propagation, and AI assistant configuration files,
The npm payload was particularly dangerous because it attempted lateral movement using stolen SSH keys to access additional machines and developer infrastructure.
Researchers also linked the campaign to a GitHub account called “ddjidd564,” which hosted malicious payloads, configuration files, and internal malware documentation via GitHub Pages.
The repository contained files such as “AUDIT-MATRIX.md,” “PAYLOAD.md,” and “BYPASS.md,” describing credential theft workflows, AI-agent abuse, prompt injection tactics, and persistence strategies.
Socket researchers said the campaign deliberately targeted high-value developer communities where crypto wallets, cloud credentials, and deployment infrastructure are commonly stored.
The fake packages impersonated developer utilities tied to DeFi tooling, Solidity optimization, AI workflows, environment setup, and blockchain infrastructure.
The attackers also attempted to expand the campaign by submitting GitHub pull requests to several prominent AI and developer projects, including LangChain, OpenHands, MetaGPT, and browser-use.
The pull requests typically proposed adding “.cursorrules” or “CLAUDE.md” files under innocent-looking titles referencing build verification or development standards.
Many of the files contained hidden instructions linked to the same malicious infrastructure used throughout the campaign.
Security researchers warned that the attack demonstrates how modern supply chain threats are evolving beyond simple malware downloads.
Instead of only targeting software dependencies, attackers are increasingly exploiting the entire developer workflow, including AI assistants, cloud environments, shell configurations, Git hooks, browser profiles, and crypto wallets.
Socket said many of the malicious packages have already been removed from public registries, though some remained active at the time of publication.
The firm added that its detection systems identified most TrapDoor releases within minutes of publication, with the fastest detection occurring just 58 seconds after a malicious package went live.
Giuseppe Ciccomascolo began his career as an investigative journalist in Italy, where he contributed to both local and national newspapers, focusing on various financial sectors.
Upon relocating to London, he worked as an analyst for Fitch's CapitalStructure and later as a Senior Reporter for Alliance News. In 2017, Giuseppe transitioned to covering cryptocurrency-related news, producing documentaries and articles on Bitcoin and other emerging digital currencies. He also played a pivotal role in establishing the academy for a cryptocurrency exchange website. Crypto remained his primary area of interest throughout his tenure as a writer for ThirdFloor.
You’re All Set!
Thanks for signing up. We’ll be in touch soon with the latest insights.
