Tuesday, May 26, 2026
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

Crypto Developers Under Siege As ‘TrapDoor’ Malware Hits Supply Chain

by DigestWire member
May 26, 2026
in Blockchain, Crypto Market, Cryptocurrency
0
Crypto Developers Under Siege As ‘TrapDoor’ Malware Hits Supply Chain
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

The attackers behind TrapDoor went after more than wallets and passwords — they embedded hidden instructions inside packages designed to manipulate AI coding assistants.

According to security firm Socket, the goal was to trick tools like Claude and Cursor into running what appeared to be routine security scans, which would then quietly discover and send out secrets stored on a developer’s machine.

Socket, a developer security platform, detected the campaign on Friday and published its findings on Sunday. Reports say the operation had already pushed out more than 34 malicious packages and 384 related versions by the time it was uncovered, with attackers continuing to release new updates across multiple software ecosystems.

🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.​io.

Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems.

TrapDoor targets… pic.twitter.com/0CI758NJ6T

— Socket (@SocketSecurity) May 24, 2026

Wallets, Keys, And Cloud Credentials All At Risk

The malware cast a wide net. Socket said TrapDoor was built to steal data from several major crypto wallets — Coinbase, Binance, Solana, Sui, Aptos, and MetaMask — as well as the Brave browser. Beyond wallet data, the malware also went after SSH keys, cloud credentials, GitHub tokens, browser extension data, and API keys.

🚨 TrapDoor supply chain attack hits npm, PyPI, and Crates-io.https://t.co/Q4ZUsUnZWY

34 malicious packages across 384 versions were used to steal crypto wallets, SSH keys, cloud credentials, and developer secrets from crypto, DeFi, Solana, and AI environments.

The malware… pic.twitter.com/GJKcgUK9RK

— The Hacker News (@TheHackersNews) May 25, 2026

The campaign spread across three major developer package repositories: npm, which serves JavaScript and Node.js developers; PyPI, used widely in Python, data science, and automation work; and Crates, the package hub for Rust developers.

Package names were chosen carefully to look like standard tools — development helpers, project setup utilities, prompt engineering packages, and Solidity or Sui build helpers — making them easy to overlook during a routine install.

Socket’s chief technology officer Ahmad Nassri said on Sunday that the GitHub activity tied to the campaign showed signs of AI-assisted development, pointing to broad security-themed templates, generic lure repositories, and a mix of partially built extraction ideas alongside working malware components.

Signs Of A Larger, Coordinated Operation

The timing of the campaign raised questions given that GitHub had reported unauthorized access to its internal repositories on May 20, just days before TrapDoor was detected. That breach followed the compromise of an employee’s device, according to reports.

Socket described TrapDoor as a coordinated attack aimed squarely at crypto, decentralized finance, AI, and security developers — communities where sensitive credentials and wallet access are common.

The campaign gave attackers broad reach precisely because the targeted developer communities often work across the same tools and ecosystems.

Featured image from Unsplash, chart from TradingView

Read Entire Article
Tags: BitcoinistBlockchainCoin Surges
Share30Tweet19
Next Post
The Democrat who thinks she can land an AI deal with Republicans

The Democrat who thinks she can land an AI deal with Republicans

Members of Congress won a battle to increase their pay. The war will go on.

Members of Congress won a battle to increase their pay. The war will go on.

‘Paddington 4’: Armando Iannucci to Write Bear’s Next Movie, ‘Paddington in Peru’ Director Dougal Wilson in Talks to Return (EXCLUSIVE)

‘Paddington 4’: Armando Iannucci to Write Bear’s Next Movie, ‘Paddington in Peru’ Director Dougal Wilson in Talks to Return (EXCLUSIVE)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

Sexiest Naked Dresses at 2026 AMAs Including Tinashe and More

BTS Wins Artist of the Year at 2026 AMAs: ‘ARMYs, We Made It Once Again’

Summer House’s Jesse Teases ‘Brutal’ Reunion Drama for Amanda and West

Russell Crowe Warns Crowd of Autograph-Seekers in Paris Not to Push: ‘As Soon as Somebody’s a D–k, I’m Going’

Giuseppe Tornatore to Be Honored With Golden Globes Prize for Documentary in Tandem With Artemis Rising Foundation at Italy’s Taormina Film Festival (EXCLUSIVE)

A Viral TikTok Claimed That Past Billie Eilish Would Think Her Current Self “Is A Loser,” And Her Big Brother, Finneas, Had Thoughts

Trending

Bairstow puts down a marker as Yorkshire march past Outlaws
Cricket

Bairstow puts down a marker as Yorkshire march past Outlaws

by DigestWire member
May 26, 2026
0

Nottinghamshire unable to find fluency with the bat as spinners lead stranglehold

Matt Taylor the mastermind as Gloucestershire sneak past Glamorgan

Matt Taylor the mastermind as Gloucestershire sneak past Glamorgan

May 26, 2026
Marsh out of Pakistan series with ankle injury, Inglis to captain

Marsh out of Pakistan series with ankle injury, Inglis to captain

May 26, 2026
Sexiest Naked Dresses at 2026 AMAs Including Tinashe and More

Sexiest Naked Dresses at 2026 AMAs Including Tinashe and More

May 26, 2026
BTS Wins Artist of the Year at 2026 AMAs: ‘ARMYs, We Made It Once Again’

BTS Wins Artist of the Year at 2026 AMAs: ‘ARMYs, We Made It Once Again’

May 26, 2026
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • Bairstow puts down a marker as Yorkshire march past Outlaws May 26, 2026
  • Matt Taylor the mastermind as Gloucestershire sneak past Glamorgan May 26, 2026
  • Marsh out of Pakistan series with ankle injury, Inglis to captain May 26, 2026

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.