TrapDoor Campaign Targets npm, PyPI, Crates.io With 34 Malicious Packages to Steal Crypto Wallets

According to security firm Socket Security, a cryptocurrency theft campaign named TrapDoor is conducting active supply chain attacks across npm, PyPI, and Crates.io package repositories today (May 25). Researchers have identified 34 malicious packages and 384 versions and artifacts, with attackers continuously releasing new iterations across ecosystems.

The campaign targets developers in cryptocurrency, DeFi, AI, and security sectors. Stolen data includes cryptocurrency wallets, SSH keys, cloud credentials, GitHub tokens, browser data, environment variables, and API keys. Socket detected malicious versions with a median detection time of 5 minutes 27 seconds, with the fastest detection occurring 58 seconds after publication.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments