< Back to all clusters

Researchers at security platform Socket identified a supply‑chain attack, dubbed “TrapDoor,” that distributes malicious packages across the npm, PyPI and Rust Crates ecosystems. More than 34 counterfeit developer packages and 384 linked versions have been observed, disguising themselves as routine utilities for project setup, model routing, Solidity frameworks and build helpers for Sui and Move applications.

The campaign targets developers working in cryptocurrency, decentralized finance, artificial intelligence and security infrastructure. Infected packages exfiltrate wallet credentials, API keys, cloud service tokens, SSH keys, GitHub tokens and browser data, enabling attackers to access wallets and services linked to Coinbase, Binance, MetaMask, Brave, Solana, Sui and Aptos. The malware also attempts to manipulate AI coding assistants such as Claude and Cursor by injecting hidden prompts during supposed security scans.

Socket’s findings place the operation within a growing pattern of supply‑chain threats aimed at crypto developers, following earlier attacks that used compromised developer tools to steal high‑value credentials.