Evidence · DiggingBeagle record
TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io
Socket documents the TrapDoor campaign across more than 34 malicious packages and 384 related versions or artifacts on npm, PyPI and Crates.io. The packages posed as developer, security, crypto and AI utilities, stole wallets and developer credentials through install, import or build-time execution, and used AI-facing files such as .cursorrules and CLAUDE.md for hidden instructions intended to make coding assistants run attacker-controlled security-scan workflows. Socket also observed campaign-linked pull requests attempting to place those AI-facing instruction files into legitimate AI and developer projects.
- Published
- May 24, 2026
- Publisher
- Socket
Evidence record
Socket documents the TrapDoor campaign across more than 34 malicious packages and 384 related versions or artifacts on npm, PyPI and Crates.io. The packages posed as developer, security, crypto and AI utilities, stole wallets and developer credentials through install, import or build-time execution, and used AI-facing files such as .cursorrules and CLAUDE.md for hidden instructions intended to make coding assistants run attacker-controlled security-scan workflows. Socket also observed campaign-linked pull requests attempting to place those AI-facing instruction files into legitimate AI and developer projects.
Claim-level citations (4)
- supportsTrapDoor disguised credential stealers as AI and security developer tools: Socket linked more than 34 malicious packages and 384 related versions or artifacts across npm, PyPI and Crates.io to the TrapDoor campaign.
Opening campaign summary and package lists across npm, PyPI and Crates.io.
- supportsTrapDoor disguised credential stealers as AI and security developer tools: Socket observed hidden AI-facing instructions and campaign-linked pull requests intended to influence coding assistants, but cautions that the technique may not work consistently across all tools and models and does not report a measured successful-compromise rate for that stage.
Sections 'AI Injection Targets Developer Assistants' and 'Attacker Opens PRs to AI and Developer Projects', including Socket's effectiveness caveat.
- supportsTrapDoor disguised credential stealers as AI and security developer tools: Socket observed TrapDoor components planting hidden instructions in .cursorrules and CLAUDE.md and campaign-linked pull requests attempting to introduce those AI-facing files into legitimate developer projects.
Sections 'AI Injection Targets Developer Assistants' and 'Attacker Opens PRs to AI and Developer Projects'.
- supportsTrapDoor disguised credential stealers as AI and security developer tools: TrapDoor packages were designed to steal developer credentials and cryptocurrency wallet material through ecosystem-specific install, import and build-time execution paths.
Sections 'What TrapDoor Steals', 'npm Packages Use Postinstall Hooks and Persistent Credential Harvesting', 'Crates.io Packages Exfiltrate Wallet Keystores' and 'PyPI Packages Execute Remote JavaScript on Import'.