TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
In order to disseminate malware that steals credentials, a new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io.
The campaign, known as TrapDoor, consists of over 384 versions of over 34 harmful programs. The first activity was noted on May 22, 2026, at 8:20 p.m. UTC, when a cluster of accounts quickly released new packages to the ecosystems in waves.
According to Socket, "TrapDoor targets developers in the crypto, DeFi, Solana, and AI communities."The malicious programs are made to collect browser data, environment variables, cloud credentials, SSH keys, cryptocurrency wallets, and developer secrets.
Several npm packages also deliver a shared payload, trap-core.js, that looks for credentials, validates AWS and GitHub tokens,...

