‘TrapDoor’ malware targets crypto dev tools in supply chain attack
Socket says a package campaign called TrapDoor is stealing crypto data and credentials by hiding malicious code inside developer tools.
Intelligence analysis by GPT-5.4 Mini

Socket says a supply-chain campaign dubbed TrapDoor is spreading malicious packages across dev ecosystems to steal wallet data, SSH keys, cloud credentials, GitHub tokens, browser data, and API keys. The campaign also appears to abuse AI coding assistants with hidden instructions.
A bad actor hid bugs inside tools that programmers like to use. Those tools looked normal, so people might download them without noticing the trick.
Once inside, the bad code tries to grab important secrets, like wallet keys and login tokens. That is like a thief sneaking into a house by pretending to be a delivery person.
The scary part is that even robot helpers used for coding may be fooled into helping the attack. That means the problem is not just one app, but the whole toolbox around it.
Analysis
What Socket found
Socket says it discovered an active supply-chain campaign on Friday and named it “TrapDoor.” The firm says the operation has pushed more than 34 malicious packages and 384 related versions, with attackers repeatedly releasing new builds across ecosystems.
Who it targets
The campaign is aimed at crypto, DeFi, AI, and security developers. According to Socket, the malware tries to steal wallet data, SSH keys, cloud credentials, GitHub tokens, browser extension data, and API keys. Socket chief technology officer Ahmad Nassri also said the malware targets popular wallets and tools including Coinbase, Binance, Solana, Sui, Aptos, MetaMask, and the Brave browser.
How the attack works
Socket says the packages are built to look like normal developer helpers: setup tools, model-routing utilities, prompt-engineering packages, and blockchain build helpers. The campaign hits common package ecosystems such as npm, PyPI, and Crates, which means it can reach JavaScript, Python, and Rust developers.
Socket also says the malware injects hidden instructions meant to “hijack your AI coding assistant,” including Claude and Cursor. The reported goal is to trick those assistants into running a fake security scan or similar task that leads to secret discovery and exfiltration.
Why the pattern matters
The article frames this as a broader shift in attacker behavior: malicious packages are being placed where developers routinely install trusted software, often without close inspection. Socket also says the GitHub activity behind the campaign shows signs of rapid, AI-assisted-style iteration, mixing lure repositories, prompt-injection documentation, and working malware pieces.
The report comes as GitHub itself said on May 20 that an employee device compromise led to unauthorized access to internal repositories, underscoring how quickly developer infrastructure can become part of the attack surface.
Key points
- Socket says it found an active supply-chain campaign it named TrapDoor.
- More than 34 malicious packages and 384 related versions were reportedly involved.
- The attack targets crypto, DeFi, AI, and security developers.
- The malware is said to steal wallet data, SSH keys, cloud credentials, GitHub tokens, browser data, and API keys.
- Socket says hidden instructions may try to manipulate AI coding assistants such as Claude and Cursor.



