TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

In order to disseminate malware that steals credentials, a new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io.

The campaign, known as TrapDoor, consists of over 384 versions of over 34 harmful programs. The first activity was noted on May 22, 2026, at 8:20 p.m. UTC, when a cluster of accounts quickly released new packages to the ecosystems in waves.

According to Socket, “TrapDoor targets developers in the crypto, DeFi, Solana, and AI communities.”The malicious programs are made to collect browser data, environment variables, cloud credentials, SSH keys, cryptocurrency wallets, and developer secrets.

Several npm packages also deliver a shared payload, trap-core.js, that looks for credentials, validates AWS and GitHub tokens, attempts SSH-based lateral movement, and plants persistence through read more about TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm PyPI and CratesIO.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *