Socket linked more than 34 malicious packages and 384 related versions or artifacts across npm, PyPI and Crates.io to the campaign it named TrapDoor. Package names such as `llm-context-compressor`, `model-switch-router`, `prompt-engineering-toolkit` and `wallet-security-checker` resembled ordinary development, security and AI utilities. The execution path…
Inspect the ClaimsCase · DiggingBeagle record
TrapDoor disguised credential stealers as AI and security developer tools
Socket found a cross-registry campaign of more than 34 malicious packages that imitated ordinary developer, security, crypto and AI utilities. The malware stole credentials and wallet material, while some components planted hidden instructions in .cursorrules and CLAUDE.md to influence AI coding assistants.
The TrapDoor supply-chain campaign reported by Socket in May 2026, covering malicious npm, PyPI and Crates.io packages that targeted crypto, DeFi, Solana, AI and security developers. The AI-security scope is the campaign's AI-themed package lures and its use of .cursorrules and CLAUDE.md as instruction surfaces for coding assistants, not a claim that every TrapDoor installation was initiated by an AI agent.
At a glance
TrapDoor separates three controls that are easy to collapse into one. Package-name and publisher verification addresses whether the dependency should be trusted at all. Install-time script restrictions address one execution route after resolution. Review of `.cursorrules`, `CLAUDE.md` and similar files addresses a later instruction boundary in which an AI…
Read the implicationsSocket establishes malicious package behavior and AI-targeted instruction files, but it does not provide a count of victims whose installations were initiated by an AI coding assistant. The public report documents theft capabilities and exfiltration paths but does not establish a quantified financial loss caused by the campaign. Socket cautions that the…
Limits and uncertaintyFull account
Socket linked more than 34 malicious packages and 384 related versions or artifacts across npm, PyPI and Crates.io to the campaign it named TrapDoor. Package names such as llm-context-compressor, model-switch-router, prompt-engineering-toolkit and wallet-security-checker resembled ordinary development, security and AI utilities. The execution path differed by ecosystem: npm packages used lifecycle hooks, PyPI packages could download and execute remote JavaScript on import, and Rust packages used build.rs during compilation. The shared objective included theft of SSH keys, cloud credentials, GitHub tokens, browser data and cryptocurrency wallet material.
TrapDoor also targeted the AI development layer after package placement. Socket found hidden zero-width instructions in .cursorrules and CLAUDE.md intended to make coding assistants run a benign-looking security workflow that led toward secret discovery and exfiltration, and it documented campaign-linked pull requests attempting to add those files to legitimate AI and developer projects. That is direct evidence of attacker intent and observed instruction planting, but not a universal success claim. Socket cautions that the technique may not work consistently across every tool and model and does not publish a measured count of assistants successfully induced to execute the hidden workflow.
npm v12's default blocking of unapproved dependency lifecycle scripts narrows the npm postinstall branch. It does not address TrapDoor's PyPI import behavior, Rust build execution, or later agent behavior driven by malicious project instructions. The campaign therefore crosses several trust boundaries rather than depending on one package-manager feature.
Claims & evidence
CLM-TRAPDOOR-CAMPAIGN-SCALESocket linked more than 34 malicious packages and 384 related versions or artifacts across npm, PyPI and Crates.io to the TrapDoor campaign.supported
Basis: reported finding
- supportsTrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.iorole not specified
Opening campaign summary and package lists across npm, PyPI and Crates.io.
CLM-TRAPDOOR-AI-INJECTION-QUALIFIERSocket observed hidden AI-facing instructions and campaign-linked pull requests intended to influence coding assistants, but cautions that the technique may not work consistently across all tools and models and does not report a measured successful-compromise rate for that stage.supported
Basis: reported finding
- supportsTrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.iorole not specified
Sections 'AI Injection Targets Developer Assistants' and 'Attacker Opens PRs to AI and Developer Projects', including Socket's effectiveness caveat.
CLM-TRAPDOOR-AI-INSTRUCTION-SURFACESocket observed TrapDoor components planting hidden instructions in .cursorrules and CLAUDE.md and campaign-linked pull requests attempting to introduce those AI-facing files into legitimate developer projects.supported
Basis: reported finding
- supportsTrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.iorole not specified
Sections 'AI Injection Targets Developer Assistants' and 'Attacker Opens PRs to AI and Developer Projects'.
CLM-TRAPDOOR-CREDENTIAL-WALLET-THEFTTrapDoor packages were designed to steal developer credentials and cryptocurrency wallet material through ecosystem-specific install, import and build-time execution paths.supported
Basis: reported finding
- supportsTrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.iorole not specified
Sections 'What TrapDoor Steals', 'npm Packages Use Postinstall Hooks and Persistent Credential Harvesting', 'Crates.io Packages Exfiltrate Wallet Keystores' and 'PyPI Packages Execute Remote JavaScript on Import'.
Implications
TrapDoor separates three controls that are easy to collapse into one. Package-name and publisher verification addresses whether the dependency should be trusted at all. Install-time script restrictions address one execution route after resolution. Review of .cursorrules, CLAUDE.md and similar files addresses a later instruction boundary in which an AI assistant may treat repository text as operational policy.
A control at only one layer leaves the others intact. npm v12 can suppress an unapproved npm lifecycle script, but that does not stop import-time code in another ecosystem or make AI-facing repository instructions trustworthy. Conversely, filtering agent instructions does not make a credential-stealing package safe.
Unknowns and contradictions
- Socket establishes malicious package behavior and AI-targeted instruction files, but it does not provide a count of victims whose installations were initiated by an AI coding assistant.
- The public report documents theft capabilities and exfiltration paths but does not establish a quantified financial loss caused by the campaign.
- Socket cautions that the AI-instruction technique may not work consistently across every tool and model, and the report does not publish a measured success rate for that stage.
- The attacker-authored design documents describe broader capabilities than Socket observed at runtime, so they should not be treated as a complete list of deployed behavior.
Sources and citation
Material revision history
- Oct 7, 2026 · Canonical change recorded · new in release · revision 88