Skip to content
Cryptocurrency and AI Developers Face New Cybersecurity Threat

Cryptocurrency and AI Developers Face New Cybersecurity Threat

Ground.News May 25, 2026

utesKey Takeaways: TrapDoor is the first documented supply chain campaign to simultaneously compromise npm, PyPI, and Crates.io registries. Socket identified more than 34 malicious packages and 384 artifacts, with a median detection time of 5 minutes and 27 seconds post-release. The malware targets AI coding tools like Cursor and Claude by embedding hidden instructions inside custom rulesets using invisible characters. Securi…

Key Takeaways A newly discovered malware campaign known as “TrapDoor” is targeting developers building on major crypto networks, including Aptos, Sui, and Solana. Researchers at ...

Blockchain security firm SlowMist warns of a cross-registry supply chain campaign targeting developers in the Solana, decentralized finance, and AI sectors to siphon private keys.

The post Cryptocurrency and AI Developers Face New Cybersecurity Threat appeared on BitcoinEthereumNews.com. A new malware campaign dubbed TrapDoor has been identified by cybersecurity firm Socket, posing a significant threat to developers in the fields of cryptocurrency and artificial intelligence. This extensive operation involves the distribution of malicious packages across popular developer platforms, targeting software developers by infilt…

The malware spread through npm, PyPI, and Rust packages in coordinated waves. It steals crypto wallets, SSH keys, and cloud developer credentials. AI coding tools were also targeted through malicious config files. A coordinated malware campaign known as TrapDoor has hit software ecosystems widely used by crypto and blockchain developers. Security researchers identified dozens of malicious packages spread across major open-source repositories, al…

A new supply-chain malware campaign named TrapDoor is targeting crypto and AI developer environments through malicious packages published across npm, PyPI and Crates.io. The campaign spans more than 34 malicious packages and 384 related versions, with payloads designed to steal SSH keys, wallet data, AWS credentials, GitHub tokens, browser profiles, API keys, environment variables and local development configuration files. The affected package n…

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage

Extracted Entities

Platforms (3)

Tools (1)