Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

TrapDoor supply chain attack spreads credential-stealing malware via npm, PyPI, CratesIO

Everyone is navigating AI security in real time, including Google

Google’s smart glasses partner Xreal thinks it has finally conquered this notoriously tricky industry

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » TrapDoor supply chain attack spreads credential-stealing malware via npm, PyPI, CratesIO
Identity

TrapDoor supply chain attack spreads credential-stealing malware via npm, PyPI, CratesIO

By May 25, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

A new coordinated cross-ecosystem software supply chain attack campaign targets npm, PyPI, and Crates.io and distributes credential-stealing malware.

The campaign, codenamed “TrapDoor,” spans over 34 malicious packages across over 384 versions. The oldest activity was recorded on May 22, 2026 at 8:20 PM UTC, when new packages were published to the ecosystem from a cluster of accounts in quick succession.

“Trapdoor targets developers in the crypto, DeFi, Solana, and AI communities,” Socket said. “The malicious package is designed to steal developer secrets, crypto wallets, SSH keys, cloud credentials, browser data, and environment variables.”

“Some npm packages also deploy a shared payload, trap-core.js, that scans credentials, validates AWS and GitHub tokens, attempts SSH-based lateral movement, and establishes persistence via .cursorrules, CLAUDE.md, Git hooks, shell hooks, systemd, cron, and SSH.”

It is worth noting that this activity is unrelated to another campaign of the same name detailed last week by HUMAN’s Satori Threat Intelligence and Investigations team for committing ad fraud by distributing 455 Android apps through the Google Play Store.

The list of identified packages is below –

Crates.io move-analyzer-build move-compiler-tools move-project-builder sui-framework-helpers sui-move-build-helper sui-sdk-build-utils npm async-pipeline-builder build-scripts-utils chain-key-validator crypto-credential-scanner defi-env-auditor defi-threat-scanner Deployment Key Audit Audit dev-env-bootstrapper eth-wallet-sentinel llm-context-compressor Mnemonic Safety Check Model Switch Router Node Setup Helper Project Initialization Tool Prompt Engineering Toolkit Solidity Deployment Guard Token Usage Tracker Wallet Backup Verifier Wallet Security Checker web3-secrets-detector workspace-config-loader PyPI cryptowallet-safety data-pipeline-check defi-risk-scanner env-loader-cli eth-security-auditor git-config-sync Solidity-build-guard

This operation is notable for its diverse delivery paths, using post-installation hooks, remote JavaScript payloads executed during package import, and malicious build.rs scripts targeting Sui and Move developers. This package disguises itself as a seemingly harmless tool, giving attackers the ability to reach a wide audience.

The npm package is known to execute a JavaScript payload (‘trap-core.js’). It scans for credentials and developer secrets, validates stolen credentials using AWS and GitHub API calls, creates persistence on the host using cron jobs, systemd services, Git hooks, and moves over the network via SSH.

Rust crates search the local keystore in a similar manner, encrypt the data using a hardcoded XOR key, and exfiltrate it to GitHub Gists. This package is also notable for its use of a build script (‘build.rs’) that triggers the execution of malicious code.

The Python packages associated with TrapDoor are designed to run automatically upon import. The main purpose of the package is to download JavaScript from the attacker-controlled GitHub Pages domain (‘ddjidd564.github’).[.]io”), run using “node -e”.

“This technique allows a Python package to delegate execution to a remote JavaScript payload, giving attackers flexibility after publication,” Socket explained. “By hosting the payload externally, an attacker can update the behavior without publishing a new PyPI release.”

What’s unusual about this campaign is that it embeds .cursorrules and CLAUDE.md that contain hidden instructions to trick artificial intelligence (AI) assistants into performing “security scans” that lead to the discovery and exfiltration of secrets. This is accomplished by opening GitHub pull requests (PRs) across common AI and developer projects such as “browser-use/browser-use”, “langchain-ai/langchain”, and “langflow-ai/langflow”.

The PR activity shows that TrapDoor does more than push malicious packages into the open source ecosystem. Socket said the attacker is likely testing whether AI-related project files can be introduced through normal open source contribution workflows, allowing AI coding tools to parse and apply these hidden instructions.

Our findings demonstrate once again that attackers are increasingly targeting developer workflows, aiming to steal a wide range of information that could allow them to penetrate deeper into the target environment for subsequent attacks.

“TrapDoor shows how attackers are combining traditional package typosquatting with new developer environment attack vectors,” Socket said. “Package names are tailored to be relevant to crypto development, AI tools, local environment setup, and security workflows. The malware uses ecosystem-specific execution paths: Rust’s build.rs, npm’s postinstall hooks, and Python’s run-on-import.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEveryone is navigating AI security in real time, including Google

Related Posts

npm adds 2FA gate exposure and package installation controls for supply chain attacks

May 23, 2026

Packagist supply chain attack infects 8 packages using Linux malware hosted on GitHub

May 23, 2026

Claude Mythos AI finds 10,000 high-severity flaws in widely used software

May 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

TrapDoor supply chain attack spreads credential-stealing malware via npm, PyPI, CratesIO

Everyone is navigating AI security in real time, including Google

Google’s smart glasses partner Xreal thinks it has finally conquered this notoriously tricky industry

TechCrunch Mobility: Robotaxis reality check

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.