PANews reported on May 25th that security company Socket Security disclosed a cryptocurrency theft campaign called TrapDoor, which is launching proactive supply chain attacks in package repositories such as npm, PyPI, and Crates.io. Currently, 34 malware packages and 384 versions and artifacts have been discovered, with attackers continuously pushing new versions across various ecosystems. TrapDoor primarily targets developers in the cryptocurrency, DeFi, AI, and security fields, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, environment variables, and API keys. Socket's median detection time for the malicious version was 5 minutes and 27 seconds, with the fastest detection occurring 58 seconds after release.
Cryptocurrency theft program TrapDoor is attacking three major code repositories; 34 malware packages have been detected.
Share to:
Author: PA一线
This content is for market information only and is not investment advice.
Follow PANews official accounts, navigate bull and bear markets together
Recommended Reading
Related Topics
PANews App
24/7 blockchain news tracking and in-depth analysis.




