HomeSecurityTrapDoor: Supply Chain Attack on npm, PyPI and CratesIO

TrapDoor: Supply Chain Attack on npm, PyPI and CratesIO

A new cross-ecosystem software supply chain attack , dubbed TrapDoor , targets the npm , PyPI , and CratesIO ecosystems to distribute credential-stealing malware . The campaign was detected by security firm Socket and includes more than 34 malicious packages in over 384 versions , with the first activity recorded on May 22, 2026. This cross-ecosystem approach represents a new evolution in supply chain attacks , as attackers leverage the specificities of each ecosystem for maximum effectiveness.

TrapDoor Supply Chain on npm, PyPI and CratesIO

The attackers specifically targeted developers working in areas such as cryptocurrency, DeFi, Solana , and artificial intelligence. The malicious packages were designed to steal sensitive developer data, including crypto wallets, SSH keys, cloud credentials, browser data, and environment variables. The attack is notable for using different delivery methods depending on the target ecosystem. The targeted nature of the campaign suggests deep knowledge of the tools and workflows used by developers in these high-value sectors.

See also: DAEMON Tools Supply Chain Attack: Government organizations targeted

In npm, malicious packages use postinstall hooks to execute a common payload named trap-core.js. This script scans for credentials, validates stolen AWS and GitHub via API calls, and attempts lateral movement via SSH. In addition, it creates persistence in the system through various methods such as .cursorrules, CLAUDE.md, Git hooks, systemd services , and cron jobs. The use of postinstall hooks is particularly dangerous as it is executed automatically after the package is installed, without requiring further interaction from the developer.

Technical Details of the TrapDoor Attack

The Python packages on PyPI are designed to execute automatically upon import. The main goal of these packages is to download JavaScript from a GitHub Pages controlled by the attackers and execute it using the node -e. This technique allows the Python package to delegate execution to a remote JavaScript payload, giving the attacker greater flexibility after publication. Using external hosting for the payload allows attackers to update the behavior of the malware without having to publish a new version to PyPI.

In CratesIO, Rust crates use malicious build.rs scripts to target Sui and Move. These packages search local keystores, encrypt the data using a hardcoded XOR key , and export it to GitHub Gists.

TrapDoor - SecNews.gr

An unusual aspect of the TrapDoor campaign is the installation of .cursorrules and CLAUDE.md containing hidden instructions to trick AI into performing a “security scan” that leads to the discovery and extraction of secrets. This is achieved by opening up GitHub pull requests to popular AI and developer projects. This tactic represents a groundbreaking approach to exploiting the AI ​​tools that more and more developers use in their daily work.

See also: Google attributes Axios Supply Chain Attack to UNC1069

Risk Protection and Mitigation Strategies

To effectively protect against TrapDoor attacks, organizations must adopt a multi-layered security approach. First, it is critical to implement strict dependency management policies, including the use of lockfiles and periodic inspection of all dependencies. Second, CI/CD systems should be configured with sandbox environments that restrict network access and sensitive files during build processes. Third, monitoring of application behavior can identify suspicious activities such as unauthorized access to SSH keys or crypto wallets.

Impact and Future Threats

The pull request activity suggests that the TrapDoor attack extends beyond simply publishing malicious packages to open source ecosystems. Socket security researchers emphasize that this campaign is unrelated to another campaign with the same name that HUMAN ’s Satori Threat Intelligence team described last week. That campaign engaged in ad fraud by distributing 455 Android apps through the Google Play Store . This coincidence of names underscores the need for careful analysis and attribution of cyber threats.

The attack is notable for its diverse delivery routes, using postinstall hooks, remote JavaScript payloads executed during package import, and malicious build.rs scripts. The packages are disguised as seemingly harmless tools, giving attackers the ability to reach a broad developer audience. Using package names that mimic legitimate security and development tools significantly increases the chances of successful installation by unscrupulous developers.

See also: Axios Supply Chain Attack: Malicious versions distribute RAT

Packagist supply chain attack with Linux malware that affected 8 packages

The TrapDoor campaign demonstrates that package registries are now part of the attack surface, while developer workstations are high-value targets.

The list of malicious packages is as follows:

  • Crates.io
    • move-analyzer-build
    • move-compiler-tools
    • move-project-builder
    • sui-framework-helpers
    • sui-move-build-helper
    • sui-sdk-build-utils
  • npm
    • async-pipeline-builder
    • build-scripts-utils
    • chain-key-validator
    • crypto-credential-scanner
    • defi-env-auditor
    • defi-threat-scanner
    • deployment-key-auditor
    • dev-env-bootstrapper
    • eth-wallet-sentinel
    • llm-context-compressor
    • mnemonic-safety-check
    • model-switch-router
    • node-setup-helpers
    • project-init-tools
    • prompt-engineering-toolkit
    • solidity-deploy-guard
    • token-usage-tracker
    • wallet-backup-verifier
    • wallet-security-checker
    • web3-secrets-detector
    • workspace-config-loader
  • PyPI
    • cryptowallet-safety
    • data-pipeline-check
    • defi-risk-scanner
    • env-loader-cli
    • eth-security-auditor
    • git-config-sync
    • solidity-build-guard
Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS