Evidence · DiggingBeagle record

TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io

Socket documents the TrapDoor campaign across more than 34 malicious packages and 384 related versions or artifacts on npm, PyPI and Crates.io. The packages posed as developer, security, crypto and AI utilities, stole wallets and developer credentials through install, import or build-time execution, and used AI-facing files such as .cursorrules and CLAUDE.md for hidden instructions intended to make coding assistants run attacker-controlled security-scan workflows. Socket also observed campaign-linked pull requests attempting to place those AI-facing instruction files into legitimate AI and developer projects.

Published
May 24, 2026
Publisher
Socket

Evidence record

Socket documents the TrapDoor campaign across more than 34 malicious packages and 384 related versions or artifacts on npm, PyPI and Crates.io. The packages posed as developer, security, crypto and AI utilities, stole wallets and developer credentials through install, import or build-time execution, and used AI-facing files such as .cursorrules and CLAUDE.md for hidden instructions intended to make coding assistants run attacker-controlled security-scan workflows. Socket also observed campaign-linked pull requests attempting to place those AI-facing instruction files into legitimate AI and developer projects.

Read the original source ↗

Claim-level citations (4)