TrapDoor Targets 34 Crypto and AI Packages Across Major Developer Platforms

TrapDoor Targets 34 Crypto and AI Packages Across Major Developer Platforms

N
News Editor 01
2026-07-24 08:10:18
The TrapDoor malware campaign is using malicious packages on npm, PyPI, and Crates to target crypto wallets, cloud credentials, and AI development workflows, including attempts to manipulate coding assistants like Claude and Cursor.

The TrapDoor malware campaign has targeted 34 cryptocurrency- and AI-related packages, aiming at developers working on crypto wallets, cloud infrastructure, and artificial intelligence tools. Named targets in the report include Coinbase, Binance, Solana, Aptos, along with wallet features tied to MetaMask and the Brave browser.

Malicious packages seek wallet credentials and cloud keys

According to the report, TrapDoor is built to steal sensitive data such as wallet credentials, SSH keys, cloud service access keys, and API authentication tokens. The risk is amplified by the way these packages are used: many are pulled into developer workflows as ordinary dependencies and may be installed without close security review.

Socket’s technical team said the campaign is engineered to go after widely used crypto wallets while hiding inside common tools used by developer communities every day. The packages often imitate legitimate projects through look-alike names, copying libraries and starter modules associated with blockchain ecosystems such as Solidity, Sui, and Move.

Hidden prompts attempt to manipulate AI coding assistants

One feature that separates TrapDoor from earlier package attacks is its use of AI-focused exploitation. The campaign embeds concealed instructions inside malicious packages to influence coding assistants including Claude and Cursor. Those instructions are designed to make the tools appear to run security checks while quietly sending sensitive data back to the attackers.

The article describes this as a form of prompt injection, where an AI model is pushed into processing harmful or unexpected commands. For teams relying on AI tools during coding, review, or debugging, that expands the attack surface beyond standard dependency poisoning.

npm, PyPI, and Crates are all part of the distribution chain

TrapDoor has spread through major open-source package platforms, including npm for JavaScript and Node.js, PyPI for Python, and Crates for the Rust ecosystem. Most of the identified packages mimic real tools, and the report says they are also circulated through AI-generated fake security frameworks and bait repositories.

Socket reported an average detection time of 5 minutes and 27 seconds for malicious packages, with the fastest detection taking just 58 seconds. GitHub also figured prominently in distribution. The article adds that on May 20, GitHub suffered an internal cyberattack after an employee’s computer was compromised, leading to unauthorized system access.

The TrapDoor campaign remains active, and the operators behind it have not been identified. Socket said it has not attributed the incident to any specific hacking group or cybercriminal organization.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.