Skip to content
TrapDoor Stealer targets npm, PyPI, and Crates.io with 34 malicious packages

TrapDoor Stealer targets npm, PyPI, and Crates.io with 34 malicious packages

Kucoin May 25, 2026

Socket Security disclosed that the TrapDoor theft program is launching supply chain attacks on code repositories such as npm, PyPI, and Crates.io, with 34 malicious packages and 384 versions and artifacts identified. The attacks target developers in the cryptocurrency, DeFi, AI, and security sectors, stealing sensitive information including wallets, SSH keys, cloud credentials, and GitHub tokens. The median detection time for malicious versions is 5 minutes and 27 seconds, with the fastest detection time at 58 seconds.

Extracted Entities

Attack Types (1)

Malware (1)

Platforms (2)

Tools (1)