Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Crypto Developers Under Siege As ‘TrapDoor’ Malware Hits Supply Chain

CryptoExpert by CryptoExpert
May 26, 2026
in Altcoin News
0
TrapDoor
  • Facebook
  • Twitter
  • Pinterest


You might also like

GSR Research Says Ethereum’s Identity Crisis Is Deepening

Big Shift For Crypto Prediction Markets: Hyperliquid Removes External Oracle Dependency

XRP Price Holds ‘Best Accumulation Zone’ as Whales Pull $170M From Binance

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

The attackers behind TrapDoor went after more than wallets and passwords — they embedded hidden instructions inside packages designed to manipulate AI coding assistants.

According to security firm Socket, the goal was to trick tools like Claude and Cursor into running what appeared to be routine security scans, which would then quietly discover and send out secrets stored on a developer’s machine.

Socket, a developer security platform, detected the campaign on Friday and published its findings on Sunday. Reports say the operation had already pushed out more than 34 malicious packages and 384 related versions by the time it was uncovered, with attackers continuing to release new updates across multiple software ecosystems.

Tokenmetrics

🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.​io.

Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems.

TrapDoor targets… pic.twitter.com/0CI758NJ6T

— Socket (@SocketSecurity) May 24, 2026

Wallets, Keys, And Cloud Credentials All At Risk

The malware cast a wide net. Socket said TrapDoor was built to steal data from several major crypto wallets — Coinbase, Binance, Solana, Sui, Aptos, and MetaMask — as well as the Brave browser. Beyond wallet data, the malware also went after SSH keys, cloud credentials, GitHub tokens, browser extension data, and API keys.

🚨 TrapDoor supply chain attack hits npm, PyPI, and Crates-io.https://t.co/Q4ZUsUnZWY

34 malicious packages across 384 versions were used to steal crypto wallets, SSH keys, cloud credentials, and developer secrets from crypto, DeFi, Solana, and AI environments.

The malware… pic.twitter.com/GJKcgUK9RK

— The Hacker News (@TheHackersNews) May 25, 2026

The campaign spread across three major developer package repositories: npm, which serves JavaScript and Node.js developers; PyPI, used widely in Python, data science, and automation work; and Crates, the package hub for Rust developers.

Package names were chosen carefully to look like standard tools — development helpers, project setup utilities, prompt engineering packages, and Solidity or Sui build helpers — making them easy to overlook during a routine install.

BTCUSD now trading at $77,245. Chart: TradingView

Socket’s chief technology officer Ahmad Nassri said on Sunday that the GitHub activity tied to the campaign showed signs of AI-assisted development, pointing to broad security-themed templates, generic lure repositories, and a mix of partially built extraction ideas alongside working malware components.

Signs Of A Larger, Coordinated Operation

The timing of the campaign raised questions given that GitHub had reported unauthorized access to its internal repositories on May 20, just days before TrapDoor was detected. That breach followed the compromise of an employee’s device, according to reports.

Socket described TrapDoor as a coordinated attack aimed squarely at crypto, decentralized finance, AI, and security developers — communities where sensitive credentials and wallet access are common.

The campaign gave attackers broad reach precisely because the targeted developer communities often work across the same tools and ecosystems.

Featured image from Unsplash, chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.





Source link

  • Facebook
  • Twitter
  • Pinterest
CryptoExpert

CryptoExpert

Recommended For You

GSR Research Says Ethereum’s Identity Crisis Is Deepening

by CryptoExpert
May 26, 2026
0
GSR Research Says Ethereum’s Identity Crisis Is Deepening

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Ethereum is facing one of its most uncomfortable periods in recent memory, with GSR Research’s...

Read more

Big Shift For Crypto Prediction Markets: Hyperliquid Removes External Oracle Dependency

by CryptoExpert
May 26, 2026
0
Hyperliquid

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Hyperliquid’s new HIP-4 update—unveiled Monday—marks a major shift in how crypto prediction markets could operate,...

Read more

XRP Price Holds ‘Best Accumulation Zone’ as Whales Pull $170M From Binance

by CryptoExpert
May 25, 2026
0
Cointelegraph

XRP (XRP) traded within a key “value zone” where whales recently accumulated $170 million, signaling a tightening liquidity supply.Key takeaways:XRP whales withdrew 122 million XRP, worth $170.8 million,...

Read more

Stablecoin Regulation: FDIC Announces New Proposed AML Rules For Issuers

by CryptoExpert
May 25, 2026
0
stablecoins

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure As crypto regulations continue to take shape in the US, the Federal Deposit Insurance Corporation...

Read more

Ethereum Price Stuck In Downtrend Despite Strong Spot Demand

by CryptoExpert
May 25, 2026
0
Ethereum Price Stuck In Downtrend Despite Strong Spot Demand

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The Ethereum price resumed its downtrend on Friday, May 22, after consolidating throughout the week....

Read more
Next Post
Post-Submission Steps for Algorand (ALGO) Change the Game Hackathon

Algorand (ALGO)'s xChain Accounts Enable EVM Wallet Use Without New Keys

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 76,448.00
ethereum
Ethereum (ETH) $ 2,077.73
tether
Tether (USDT) $ 0.998722
bnb
BNB (BNB) $ 659.01
xrp
XRP (XRP) $ 1.34
usd-coin
USDC (USDC) $ 0.999728
solana
Solana (SOL) $ 84.15
tron
TRON (TRX) $ 0.374652
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?