Skip to content
TrapDoor crypto theft campaign affects 34+ malicious packages across npm, PyPI, and Crates.io

TrapDoor crypto theft campaign affects 34+ malicious packages across npm, PyPI, and Crates.io

Kucoin May 25, 2026

According to ME News, on May 25 (UTC+8), security firm Socket Security discovered a supply chain attack named TrapDoor, a cryptocurrency-stealing campaign involving over 34 malicious packages and 384 associated versions across npm, PyPI, and Crates.io platforms. The attack primarily targets developers in cryptocurrency, DeFi, Solana, Sui, Move, and AI. The attack method includes stealing SSH keys, wallet data, AWS credentials, GitHub tokens, browser data, and environment variables. Specifically: npm packages execute trap-core.js via postinstall hooks; PyPI packages run remote JavaScript upon import; and Crates.io packages exploit build.rs to harvest local keychains. Socket has flagged these malicious packages and reported them to the respective package registries. (Source: MLion)