Charts
DataOn-chain
VIP
Market Cap
API
Rankings
CoinOSNew
CoinClaw
Language
  • 简体中文
  • 繁体中文
  • English
Leader in global market data applications, committed to providing valuable information more efficiently.

Features

  • Real-time Data
  • Special Features
  • AI Grid

Services

  • News
  • Open Data(API)
  • Institutional Services

Downloads

  • Desktop
  • Android
  • iOS

Contact Us

  • Chat Room
  • Business Email
  • Official Email
  • Official Verification

Join Community

  • Telegram
  • Twitter
  • Discord

© Copyright 2013-2026. All rights reserved.

简体繁體English
|Legacy

Trapdoor Malware: The Massive Supply Chain Attack Targeting Crypto Developers

CN
bitcoin.com
Follow
2 hours ago
AI summarizes in 5 seconds.

  • Key Takeaways:

    • On May 22, Socket found Trapdoor malware infecting 34 developer packages to steal crypto wallets and keys.
    • Spanning 384 versions, the campaign tricks AI tools and severely impacts the development market.
    • After a similar September attack, Socket warns developers must next secure AI environments from crypto theft.
  • While some malware campaigns target everyday crypto users, others focus on developers, aiming to capture targets with a higher chance of holding large amounts of cryptocurrency and having access to broader resources.

    Researchers at Socket, a company that specializes in preventing supply chain attacks, have identified a broad campaign targeting crypto developers using infected packages across npm, PyPI, and Crates.io.

    Trapdoor Malware: The Massive Supply Chain Attack Targeting Crypto Developers

    Dubbed Trapdoor, the supply chain attack spans 34 packages across these development environments, encompassing over 384 versions, with some still available. Socket reported that the affected packages were published in waves starting on May 22 and then were updated throughout the following weekend.

    The packages stood out due to their nature, as they allegedly represented generic developer tools and appeared in quick succession across different registries. This gives the campaign “broad reach across adjacent developer communities where crypto wallets, cloud credentials, Github tokens, and SSH keys are likely to be present,” socket assessed.

    The infected packages invade the development environment of crypto developers, leveraging these alleged open-source tools, taking hold of secrets, crypto wallets, secure shell (SSH) keys, and other relevant data.

    Trapdoor infected packages also try to leverage AI tools to collaborate with their attack, using directive files to trick AI coding tools to run a security scan and exfiltrate highly sensitive data.

    Socket stated that while this technique could not work consistently across all AI tools and models, its presence shows that attackers “are actively experimenting with AI development environments as part of supply chain malware campaigns.”

    Chain attacks are becoming more common. In September, the crypto community was alerted about a similar hack, with several packages used by crypto wallets being compromised and modified to steal cryptocurrency funds from wallets containing bitcoin, ether, and solana, among other digital assets.

    免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

    |
    |
    APP
    Windows
    Mac
    Share To

    X

    Telegram

    Facebook

    Reddit

    CopyLink

    |
    |
    APP
    Windows
    Mac
    Share To

    X

    Telegram

    Facebook

    Reddit

    CopyLink

    Selected Articles by bitcoin.com

    24 minutes ago
    Bitcoin Seizure Links Chinese National’s Binance Account to DOJ Case
    1 hour ago
    Robert Kiyosaki Links Iran Yuan Oil Move to US Dollar ‘Death’ Warning
    3 hours ago
    Whale Who Spent $62M on Uniswap and Compound Tokens Is Now Selling at a $39.7M Loss
    View More

    Table of Contents

    |
    |
    APP
    Windows
    Mac
    Share To

    X

    Telegram

    Facebook

    Reddit

    CopyLink

    Related Articles

    avatar
    avatarbitcoin.com
    24 minutes ago
    Bitcoin Seizure Links Chinese National’s Binance Account to DOJ Case
    avatar
    avatarbitcoin.com
    1 hour ago
    Robert Kiyosaki Links Iran Yuan Oil Move to US Dollar ‘Death’ Warning
    avatar
    avatarbitcoin.com
    3 hours ago
    Whale Who Spent $62M on Uniswap and Compound Tokens Is Now Selling at a $39.7M Loss
    avatar
    avatarbitcoin.com
    4 hours ago
    Bitcoin ETFs Lose $1.26B as XRP and HYPE Funds Attract Fresh Inflows
    APP
    Windows
    Mac

    X

    Telegram

    Facebook

    Reddit

    CopyLink