Case · DiggingBeagle record

TrapDoor disguised credential stealers as AI and security developer tools

Socket found a cross-registry campaign of more than 34 malicious packages that imitated ordinary developer, security, crypto and AI utilities. The malware stole credentials and wallet material, while some components planted hidden instructions in .cursorrules and CLAUDE.md to influence AI coding assistants.

Scope

The TrapDoor supply-chain campaign reported by Socket in May 2026, covering malicious npm, PyPI and Crates.io packages that targeted crypto, DeFi, Solana, AI and security developers. The AI-security scope is the campaign's AI-themed package lures and its use of .cursorrules and CLAUDE.md as instruction surfaces for coding assistants, not a claim that every TrapDoor installation was initiated by an AI agent.

UnratedAI role: WITH AIAssessment method

At a glance

Claims & evidence

CLM-TRAPDOOR-CAMPAIGN-SCALESocket linked more than 34 malicious packages and 384 related versions or artifacts across npm, PyPI and Crates.io to the TrapDoor campaign.supported

Basis: reported finding

Link to claim
CLM-TRAPDOOR-AI-INJECTION-QUALIFIERSocket observed hidden AI-facing instructions and campaign-linked pull requests intended to influence coding assistants, but cautions that the technique may not work consistently across all tools and models and does not report a measured successful-compromise rate for that stage.supported

Basis: reported finding

Link to claim
CLM-TRAPDOOR-AI-INSTRUCTION-SURFACESocket observed TrapDoor components planting hidden instructions in .cursorrules and CLAUDE.md and campaign-linked pull requests attempting to introduce those AI-facing files into legitimate developer projects.supported

Basis: reported finding

Link to claim
CLM-TRAPDOOR-CREDENTIAL-WALLET-THEFTTrapDoor packages were designed to steal developer credentials and cryptocurrency wallet material through ecosystem-specific install, import and build-time execution paths.supported

Basis: reported finding

Link to claim

Implications

TrapDoor separates three controls that are easy to collapse into one. Package-name and publisher verification addresses whether the dependency should be trusted at all. Install-time script restrictions address one execution route after resolution. Review of .cursorrules, CLAUDE.md and similar files addresses a later instruction boundary in which an AI assistant may treat repository text as operational policy.

A control at only one layer leaves the others intact. npm v12 can suppress an unapproved npm lifecycle script, but that does not stop import-time code in another ecosystem or make AI-facing repository instructions trustworthy. Conversely, filtering agent instructions does not make a credential-stealing package safe.

Unknowns and contradictions

  • Socket establishes malicious package behavior and AI-targeted instruction files, but it does not provide a count of victims whose installations were initiated by an AI coding assistant.
  • The public report documents theft capabilities and exfiltration paths but does not establish a quantified financial loss caused by the campaign.
  • Socket cautions that the AI-instruction technique may not work consistently across every tool and model, and the report does not publish a measured success rate for that stage.
  • The attacker-authored design documents describe broader capabilities than Socket observed at runtime, so they should not be treated as a complete list of deployed behavior.

Sources and citation

Material revision history

  1. Oct 7, 2026 · Canonical change recorded · new in release · revision 88