Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Crypto Developers Under Siege As ‘TrapDoor’ Malware Hits Supply Chain

CryptoExpert by CryptoExpert
May 26, 2026
in Altcoin News
0
TrapDoor
  • Facebook
  • Twitter
  • Pinterest


You might also like

Bitcoin Is Going According To Plan: Analyst Who Predicted $59,000 Reveals What’s Next

Zcash developers propose ‘Ironwood’ upgrade, ZEC price rebounds, but there is a risk

FTX Co-Founder Bankman-Fried Requests Trump Pardon–FTT Soars 45%

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

The attackers behind TrapDoor went after more than wallets and passwords — they embedded hidden instructions inside packages designed to manipulate AI coding assistants.

According to security firm Socket, the goal was to trick tools like Claude and Cursor into running what appeared to be routine security scans, which would then quietly discover and send out secrets stored on a developer’s machine.

Socket, a developer security platform, detected the campaign on Friday and published its findings on Sunday. Reports say the operation had already pushed out more than 34 malicious packages and 384 related versions by the time it was uncovered, with attackers continuing to release new updates across multiple software ecosystems.

okex

🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.​io.

Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems.

TrapDoor targets… pic.twitter.com/0CI758NJ6T

— Socket (@SocketSecurity) May 24, 2026

Wallets, Keys, And Cloud Credentials All At Risk

The malware cast a wide net. Socket said TrapDoor was built to steal data from several major crypto wallets — Coinbase, Binance, Solana, Sui, Aptos, and MetaMask — as well as the Brave browser. Beyond wallet data, the malware also went after SSH keys, cloud credentials, GitHub tokens, browser extension data, and API keys.

🚨 TrapDoor supply chain attack hits npm, PyPI, and Crates-io.https://t.co/Q4ZUsUnZWY

34 malicious packages across 384 versions were used to steal crypto wallets, SSH keys, cloud credentials, and developer secrets from crypto, DeFi, Solana, and AI environments.

The malware… pic.twitter.com/GJKcgUK9RK

— The Hacker News (@TheHackersNews) May 25, 2026

The campaign spread across three major developer package repositories: npm, which serves JavaScript and Node.js developers; PyPI, used widely in Python, data science, and automation work; and Crates, the package hub for Rust developers.

Package names were chosen carefully to look like standard tools — development helpers, project setup utilities, prompt engineering packages, and Solidity or Sui build helpers — making them easy to overlook during a routine install.

BTCUSD now trading at $77,245. Chart: TradingView

Socket’s chief technology officer Ahmad Nassri said on Sunday that the GitHub activity tied to the campaign showed signs of AI-assisted development, pointing to broad security-themed templates, generic lure repositories, and a mix of partially built extraction ideas alongside working malware components.

Signs Of A Larger, Coordinated Operation

The timing of the campaign raised questions given that GitHub had reported unauthorized access to its internal repositories on May 20, just days before TrapDoor was detected. That breach followed the compromise of an employee’s device, according to reports.

Socket described TrapDoor as a coordinated attack aimed squarely at crypto, decentralized finance, AI, and security developers — communities where sensitive credentials and wallet access are common.

The campaign gave attackers broad reach precisely because the targeted developer communities often work across the same tools and ecosystems.

Featured image from Unsplash, chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.





Source link

  • Facebook
  • Twitter
  • Pinterest
CryptoExpert

CryptoExpert

Recommended For You

Bitcoin Is Going According To Plan: Analyst Who Predicted $59,000 Reveals What’s Next

by CryptoExpert
June 9, 2026
0
Bitcoin bombshell

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Despite the Bitcoin crash to $59,000 triggering extreme fear across the crypto market, not everyone...

Read more

Zcash developers propose ‘Ironwood’ upgrade, ZEC price rebounds, but there is a risk

by CryptoExpert
June 9, 2026
0
Zcash (ZEC)

Zcash’s Orchard pool bug, undetected since 2022, sent ZEC crashing 52% to $303. The proposed Ironwood upgrade lets anyone verify ZEC’s 21 million coin supply cap. Analyst Yashu...

Read more

FTX Co-Founder Bankman-Fried Requests Trump Pardon–FTT Soars 45%

by CryptoExpert
June 8, 2026
0
FTX

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Sam Bankman-Fried, the co-founder and former CEO of the collapsed cryptocurrency exchange FTX, moved forward...

Read more

Arthur Hayes Dumps Worldcoin After Bullish AI Proxy Call

by CryptoExpert
June 8, 2026
0
Arthur Hayes Dumps Worldcoin After Bullish AI Proxy Call

Maelstrom co-founder Arthur Hayes said he sold his Worldcoin (WLD) holdings just days after his venture capital firm described it as one of the cleanest proxies for the...

Read more

Crypto Moves Into The Mainstream Of Vietnam’s Digital Economy

by CryptoExpert
June 8, 2026
0
crypto

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Vietnam is planning to require that all domestic crypto trading — including transactions in Bitcoin,...

Read more
Next Post
Post-Submission Steps for Algorand (ALGO) Change the Game Hackathon

Algorand (ALGO)'s xChain Accounts Enable EVM Wallet Use Without New Keys

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 61,560.00
ethereum
Ethereum (ETH) $ 1,640.42
tether
Tether (USDT) $ 0.999192
bnb
BNB (BNB) $ 590.34
usd-coin
USDC (USDC) $ 0.999821
xrp
XRP (XRP) $ 1.13
solana
Solana (SOL) $ 64.44
tron
TRON (TRX) $ 0.322385
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?