Back Kucoin TrapDoor crypto theft campaign affects 34+ malicious packages across npm, PyPI, and Crates.io
According to ME News, on May 25 (UTC+8), security firm Socket Security discovered a supply chain attack named TrapDoor, a cryptocurrency-stealing campaign involving over 34 malicious packages and 384 associated versions across npm, PyPI, and Crates.io platforms. The attack primarily targets developers in cryptocurrency, DeFi, Solana, Sui, Move, and AI. The attack method includes stealing SSH keys, wallet data, AWS credentials, GitHub tokens, browser data, and environment variables. Specifically: npm packages execute trap-core.js via postinstall hooks; PyPI packages run remote JavaScript upon import; and Crates.io packages exploit build.rs to harvest local keychains. Socket has flagged these malicious packages and reported them to the respective package registries. (Source: MLion)
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
