The attackers behind TrapDoor didn’t limit themselves to wallets and passwords: they embedded hidden instructions in packages designed to manipulate the AI’s coding assistants.
According to security firm Socket, the goal was to trick tools like Claude and Cursor into running what appeared to be routine security scans, which would then uncover and discreetly send secrets stored on a developer’s machine.
Socket, a developer security platform, detected the campaign on Friday and published its findings on Sunday. Reports indicate that the operation had already released more than 34 malicious packages and 384 associated versions by the time it was discovered, with the attackers continuing to release new updates across multiple software ecosystems.
🚨 BREAK: Active supply chain attack on npm, PyPI and Crates.io.
Socket detected TrapDoor, a cryptocurrency theft campaign affecting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly releasing new versions across ecosystems.
TrapDoor targets… pic.twitter.com/0CI758NJ6T
– Socket (@SocketSecurity) May 24, 2026
Wallets, keys and cloud credentials are all at risk
The malware has cast a wide net. Socket said TrapDoor was designed to steal data from several major crypto wallets – Coinbase, Binance, Solana, Sui, Aptos and MetaMask – as well as the Brave browser. Beyond wallet data, the malware also attacked SSH keys, cloud credentials, GitHub tokens, browser extension data, and API keys.
🚨 TrapDoor supply chain attack hits npm, PyPI and Crates-io.
34 malware packages across 384 versions were used to steal crypto wallets, SSH keys, cloud credentials, and developer secrets across crypto, DeFi, Solana, and AI environments.
The malware… pic.twitter.com/GJKcgUK9RK
– Hacker News (@TheHackersNews) May 25, 2026
The campaign expanded to three major developer package repositories: npm, which serves JavaScript and Node.js developers; PyPI, widely used in Python, data science and automation work; and Crates, the packages hub for Rust developers.
The package names have been carefully chosen to resemble standard tools (development aids, project setup utilities, quick engineering packages, and Solidity or Sui build aids), making them easy to overlook during a routine installation.
Ahmad Nassri, chief technology officer at Socket, said on Sunday that GitHub activity related to the campaign showed signs of AI-assisted development, highlighting extensive security-themed models, generic lure repositories, and a mix of partially constructed extraction ideas alongside working malware components.

Signs of a larger, coordinated operation
The timing of the campaign raised questions given that GitHub had reported unauthorized access to its internal repositories on May 20, just days before TrapDoor was detected. This breach followed the compromise of an employee’s device, according to reports.
Socket described TrapDoor as a coordinated attack directly targeting crypto, decentralized finance, AI, and security developers – communities where sensitive credentials and wallet access are common.
The campaign gave the attackers broad reach, precisely because the targeted developer communities often work with the same tools and ecosystems.
Featured image from Unsplash, chart from TradingView
Editorial process as Bitcoinist focuses on providing thoroughly researched, accurate and unbiased content. We follow strict sourcing standards and every page undergoes careful review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance and value of our content to our readers.


