Back Kucoin TrapDoor Crypto Theft Campaign Targets npm, PyPI, and Crates.io with 34+ Malicious Packages
According to research by security firm Socket Security, a cryptocurrency-stealing supply chain attack named TrapDoor spans npm, PyPI, and Crates.io, involving over 34 malicious packages and 384 associated versions and artifacts, targeting developers in cryptocurrency, DeFi, Solana, Sui, Move, and AI. The attack samples steal sensitive information such as SSH keys, wallet data, AWS credentials, GitHub tokens, browser data, and environment variables. npm packages execute a shared payload, trap-core.js, via postinstall hooks; PyPI packages execute remote JavaScript upon import; and Crates.io packages leverage build.rs to steal local keychains. Socket has flagged all related packages as malicious and reported them to the respective package registries.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
