A new cross-ecosystem software supply chain attack , dubbed TrapDoor , targets the npm , PyPI , and CratesIO ecosystems to distribute credential-stealing malware . The campaign was detected by security firm Socket and includes more than 34 malicious packages in over 384 versions , with the first activity recorded on May 22, 2026. This cross-ecosystem approach represents a new evolution in supply chain attacks , as attackers leverage the specificities of each ecosystem for maximum effectiveness.

The attackers specifically targeted developers working in areas such as cryptocurrency, DeFi, Solana , and artificial intelligence. The malicious packages were designed to steal sensitive developer data, including crypto wallets, SSH keys, cloud credentials, browser data, and environment variables. The attack is notable for using different delivery methods depending on the target ecosystem. The targeted nature of the campaign suggests deep knowledge of the tools and workflows used by developers in these high-value sectors.
See also: DAEMON Tools Supply Chain Attack: Government organizations targeted
In npm, malicious packages use postinstall hooks to execute a common payload named trap-core.js. This script scans for credentials, validates stolen AWS and GitHub via API calls, and attempts lateral movement via SSH. In addition, it creates persistence in the system through various methods such as .cursorrules, CLAUDE.md, Git hooks, systemd services , and cron jobs. The use of postinstall hooks is particularly dangerous as it is executed automatically after the package is installed, without requiring further interaction from the developer.
Technical Details of the TrapDoor Attack
The Python packages on PyPI are designed to execute automatically upon import. The main goal of these packages is to download JavaScript from a GitHub Pages controlled by the attackers and execute it using the node -e. This technique allows the Python package to delegate execution to a remote JavaScript payload, giving the attacker greater flexibility after publication. Using external hosting for the payload allows attackers to update the behavior of the malware without having to publish a new version to PyPI.
In CratesIO, Rust crates use malicious build.rs scripts to target Sui and Move. These packages search local keystores, encrypt the data using a hardcoded XOR key , and export it to GitHub Gists.

An unusual aspect of the TrapDoor campaign is the installation of .cursorrules and CLAUDE.md containing hidden instructions to trick AI into performing a “security scan” that leads to the discovery and extraction of secrets. This is achieved by opening up GitHub pull requests to popular AI and developer projects. This tactic represents a groundbreaking approach to exploiting the AI tools that more and more developers use in their daily work.
See also: Google attributes Axios Supply Chain Attack to UNC1069
Risk Protection and Mitigation Strategies
To effectively protect against TrapDoor attacks, organizations must adopt a multi-layered security approach. First, it is critical to implement strict dependency management policies, including the use of lockfiles and periodic inspection of all dependencies. Second, CI/CD systems should be configured with sandbox environments that restrict network access and sensitive files during build processes. Third, monitoring of application behavior can identify suspicious activities such as unauthorized access to SSH keys or crypto wallets.
Impact and Future Threats
The pull request activity suggests that the TrapDoor attack extends beyond simply publishing malicious packages to open source ecosystems. Socket security researchers emphasize that this campaign is unrelated to another campaign with the same name that HUMAN ’s Satori Threat Intelligence team described last week. That campaign engaged in ad fraud by distributing 455 Android apps through the Google Play Store . This coincidence of names underscores the need for careful analysis and attribution of cyber threats.
The attack is notable for its diverse delivery routes, using postinstall hooks, remote JavaScript payloads executed during package import, and malicious build.rs scripts. The packages are disguised as seemingly harmless tools, giving attackers the ability to reach a broad developer audience. Using package names that mimic legitimate security and development tools significantly increases the chances of successful installation by unscrupulous developers.
See also: Axios Supply Chain Attack: Malicious versions distribute RAT

The TrapDoor campaign demonstrates that package registries are now part of the attack surface, while developer workstations are high-value targets.
The list of malicious packages is as follows:
- Crates.io
- move-analyzer-build
- move-compiler-tools
- move-project-builder
- sui-framework-helpers
- sui-move-build-helper
- sui-sdk-build-utils
- npm
- async-pipeline-builder
- build-scripts-utils
- chain-key-validator
- crypto-credential-scanner
- defi-env-auditor
- defi-threat-scanner
- deployment-key-auditor
- dev-env-bootstrapper
- eth-wallet-sentinel
- llm-context-compressor
- mnemonic-safety-check
- model-switch-router
- node-setup-helpers
- project-init-tools
- prompt-engineering-toolkit
- solidity-deploy-guard
- token-usage-tracker
- wallet-backup-verifier
- wallet-security-checker
- web3-secrets-detector
- workspace-config-loader
- PyPI
- cryptowallet-safety
- data-pipeline-check
- defi-risk-scanner
- env-loader-cli
- eth-security-auditor
- git-config-sync
- solidity-build-guard
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
