Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Crypto Developers Under Siege As ‘TrapDoor’ Malware Hits Supply Chain

CryptoExpert by CryptoExpert
May 26, 2026
in Altcoin News
0
TrapDoor
  • Facebook
  • Twitter
  • Pinterest


You might also like

Kraken, Maple Launch Onchain Warehouse Facility for Crypto Loans

MemeCore Token Crashes As ZachXBT Warning Puts Insider Supply Back In Focus

21Shares Says Bitcoin Can Still Recover Toward $100,000 Despite Market Shakeout

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

The attackers behind TrapDoor went after more than wallets and passwords — they embedded hidden instructions inside packages designed to manipulate AI coding assistants.

According to security firm Socket, the goal was to trick tools like Claude and Cursor into running what appeared to be routine security scans, which would then quietly discover and send out secrets stored on a developer’s machine.

Socket, a developer security platform, detected the campaign on Friday and published its findings on Sunday. Reports say the operation had already pushed out more than 34 malicious packages and 384 related versions by the time it was uncovered, with attackers continuing to release new updates across multiple software ecosystems.

okex

🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.​io.

Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems.

TrapDoor targets… pic.twitter.com/0CI758NJ6T

— Socket (@SocketSecurity) May 24, 2026

Wallets, Keys, And Cloud Credentials All At Risk

The malware cast a wide net. Socket said TrapDoor was built to steal data from several major crypto wallets — Coinbase, Binance, Solana, Sui, Aptos, and MetaMask — as well as the Brave browser. Beyond wallet data, the malware also went after SSH keys, cloud credentials, GitHub tokens, browser extension data, and API keys.

🚨 TrapDoor supply chain attack hits npm, PyPI, and Crates-io.https://t.co/Q4ZUsUnZWY

34 malicious packages across 384 versions were used to steal crypto wallets, SSH keys, cloud credentials, and developer secrets from crypto, DeFi, Solana, and AI environments.

The malware… pic.twitter.com/GJKcgUK9RK

— The Hacker News (@TheHackersNews) May 25, 2026

The campaign spread across three major developer package repositories: npm, which serves JavaScript and Node.js developers; PyPI, used widely in Python, data science, and automation work; and Crates, the package hub for Rust developers.

Package names were chosen carefully to look like standard tools — development helpers, project setup utilities, prompt engineering packages, and Solidity or Sui build helpers — making them easy to overlook during a routine install.

BTCUSD now trading at $77,245. Chart: TradingView

Socket’s chief technology officer Ahmad Nassri said on Sunday that the GitHub activity tied to the campaign showed signs of AI-assisted development, pointing to broad security-themed templates, generic lure repositories, and a mix of partially built extraction ideas alongside working malware components.

Signs Of A Larger, Coordinated Operation

The timing of the campaign raised questions given that GitHub had reported unauthorized access to its internal repositories on May 20, just days before TrapDoor was detected. That breach followed the compromise of an employee’s device, according to reports.

Socket described TrapDoor as a coordinated attack aimed squarely at crypto, decentralized finance, AI, and security developers — communities where sensitive credentials and wallet access are common.

The campaign gave attackers broad reach precisely because the targeted developer communities often work across the same tools and ecosystems.

Featured image from Unsplash, chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.





Source link

  • Facebook
  • Twitter
  • Pinterest
CryptoExpert

CryptoExpert

Recommended For You

Kraken, Maple Launch Onchain Warehouse Facility for Crypto Loans

by CryptoExpert
June 25, 2026
0
Cointelegraph

Crypto exchange Kraken and onchain asset manager Maple have launched an onchain warehouse financing facility for crypto-backed loans, applying a lending structure widely used in traditional credit markets...

Read more

MemeCore Token Crashes As ZachXBT Warning Puts Insider Supply Back In Focus

by CryptoExpert
June 25, 2026
0
memecore

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure MemeCore’s M token plunged in a sudden sell-off, reviving concerns about thin liquidity, insider supply...

Read more

21Shares Says Bitcoin Can Still Recover Toward $100,000 Despite Market Shakeout

by CryptoExpert
June 25, 2026
0
Bitcoin

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure TL;DR 21Shares says Bitcoin remains under pressure but still has a path back toward...

Read more

Mining Profits Dry Up Across Bitcoin, DOGE, LTC, and BCH

by CryptoExpert
June 24, 2026
0
Bitcoin Mining Industry Generates 31,000+ Jobs in the US: Report

Dogecoin and Litecoin miners face mounting pressure as mining profitability remains low across major proof-of-work assets. Cryptocurrency mining profitability remains under pressure across major proof-of-work networks, according...

Read more

CryptoQuant Says Strategy Should Pause Bitcoin Buys And Rebuild Cash Reserves

by CryptoExpert
June 24, 2026
0
CryptoQuant

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure TL;DR CryptoQuant says Strategy should pause Bitcoin purchases and rebuild cash reserves. The warning...

Read more
Next Post
Post-Submission Steps for Algorand (ALGO) Change the Game Hackathon

Algorand (ALGO)'s xChain Accounts Enable EVM Wallet Use Without New Keys

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 59,695.00
ethereum
Ethereum (ETH) $ 1,566.02
tether
Tether (USDT) $ 0.998459
bnb
BNB (BNB) $ 560.86
usd-coin
USDC (USDC) $ 0.999648
xrp
XRP (XRP) $ 1.04
solana
Solana (SOL) $ 67.82
tron
TRON (TRX) $ 0.323497
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?