Close Menu
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Categories
  • Altcoins (3,699)
  • Analysis (3,807)
  • Bitcoin (4,435)
  • Blockchain (2,157)
  • DeFi (2,623)
  • Ethereum (2,767)
  • Event (119)
  • Exclusive Deep Dive (1)
  • Landscape Ads (2)
  • Market (2,714)
  • Press Releases (12)
  • Reddit (2,847)
  • Regulation (2,474)
  • Security (4,075)
  • Thought Leadership (3)
  • Videos (44)
Hand picked
  • Bitcoin ETF News: $273M in Inflows – What’s Driving the Institutional Turnaround?
  • Grayscale Files for a Worldcoin ETF as WLD Jumps 8% – What’s Next?
  • Aave chooses Chainlink CCIP as default standard for cross-chain sGHO
  • Strategy Says Bitcoin Reserve Offers 31 Years of Dividend Coverage as Cash Reserve Reaches $3.2 Billion
  • Jito Jumps 12% After JIP-38 Buyback Proposal – Can JTO Hit $0.80?
We are social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Facebook X (Twitter) Instagram
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
Facebook X (Twitter) Instagram YouTube LinkedIn
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Events
Altcoin ObserverAltcoin Observer
Home»Security»TrapDoor malware targets data from Solana, Sui and Aptos wallets
Security

TrapDoor malware targets data from Solana, Sui and Aptos wallets

May 30, 2026No Comments
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Stake Banner

A new cryptocurrency theft campaign targets developers who likely have wallet keys, cloud credentials, and production access on their machines. Researchers at security firm Socket reported earlier this week that they had identified a supply chain attack called TrapDoor that was spreading across three major open source programming registries. The attack includes more than 34 malware packages with hundreds of versions and associated artifacts.

What you have to remember is that attackers are becoming more and more concentrated. Beyond social engineering that targets individuals with key information, supply chain attacks are not designed to catch random retail users but developers. These are precisely the people who can have wallet files, SSH keys, GitHub tokens, cloud credentials, and production access on the same machine they use to build crypto and AI tools.

Socket has not identified specific victims or stolen funds. But the company said the packages are available on npm, PyPI and Crates.io. These packages contained payloads capable of stealing wallet data, exfiltrating credentials, testing AWS and GitHub tokens, and leaving files to maintain active access.

Boring by design

The packages were programmed in JavaScript, Python and Rust. They were disguised as developer aids, security scanners, wallet tools, Solidity utilities, AI prompt packages, and Sui or Move build aids. The names were intentionally boring: “wallet-security-checker”, “defi-risk-scanner”, “solidity-build-guard”, “move-compiler-tools” and “llm-context-compressor”. It looked like the kind of little utility a crypto or AI developer might install without much thought.

However, once installed, the payloads attempted to extract much more than package data. In npm packages, the malware searched a developer’s machine for private keys, passwords, GitHub tokens, and cloud logins. It also tested some stolen credentials, attempted to move to other systems via SSH keys, and left behind files that could keep the infection active.

SSH keys are login files that developers use to access servers, code repositories, and other machines. If stolen, they can allow an attacker to move from a compromised laptop into a company’s broader infrastructure.

AI tools as attack vectors

The attack also uses files such as .cursorrules and claude.md, which allow developers to give project-specific instructions to AI coding tools. Socket said the campaign implemented hidden instructions using zero-width Unicode characters. These appear to be trying to get future AI assistant sessions to run fake “security scans” that collect and exfiltrate secrets.

This transformed the attack from a normal packet stealer into something closer to malware aimed at the development environment. Installing the package is just the first step. The real target is the desktop: wallets, repositories, browser data, cloud keys, SSH access, and whatever else the AI ​​coding tools will read next.

Rust packages used malicious build.rs scripts to run during compilation, targeting Sui and Move developers. PyPI packages executed JavaScript remotely during import. Packages on npm used post-installation hooks.

Socket said it reported the packages to relevant registries and classified the campaign packages as malicious. The company also warned that the attacker opened pull requests to AI and developer projects, attempting to add .cursorrules and CLAUDE.md files via normal open source contribution paths.

Loading



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDaily Crypto Discussion – May 14, 2026 (GMT+0)
Next Article Crypto News Today (May 28): Crypto Crash as BTC Nears $70,000 as Blackrock Dumps Over $500 Million in Bitcoin

Related Posts

Security

Online Pokies Time Launches Independent Real Money Testing Framework to Improve Transparency of Online Casino Reviews

July 20, 2026
Security

CryptoMondays Europe Announces “Unfiltered Bitcoin” Fireside Chat with Giacomo Zucco.

July 20, 2026
Security

Virtuals Protocol Launches Tokenized Indexes on Robinhood Chain

July 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Single Page Post
Share
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Featured Content
Event

Dutch Blockchain Week 2026 strengthens position as Europe’s leading B2B blockchain event week

April 14, 2026

Amsterdam, April 2026 – Dutch Blockchain Week 2026 is rapidly evolving into one of Europe’s…

Event

Global Games Show Riyadh: The Ultimate Creator & Influencer Hub

March 31, 2026

The fast-evolving gaming ecosystem of Riyadh is powered by solid national investment, a flourishing esports…

1 2 3 … 82 Next
  • Facebook
  • Twitter
  • Instagram
  • YouTube

Grayscale Files for a Worldcoin ETF as WLD Jumps 8% – What’s Next?

July 21, 2026

Jito Jumps 12% After JIP-38 Buyback Proposal – Can JTO Hit $0.80?

July 21, 2026

Can Pi Network’s v25 protocol upgrade push PI price to $0.12?

July 20, 2026
Facebook X (Twitter) Instagram LinkedIn
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
© 2026 Altcoin Observer. all rights reserved by Tech Team.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 66,553.00
ethereum
Ethereum (ETH) $ 1,926.45
tether
Tether (USDT) $ 0.999398
bnb
BNB (BNB) $ 574.36
usd-coin
USDC (USDC) $ 0.999828
xrp
XRP (XRP) $ 1.15
solana
Solana (SOL) $ 78.14
tron
TRON (TRX) $ 0.328424
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.00
staked-ether
Lido Staked Ether (STETH) $ 2,265.05