On May 25, security company Socket Security revealed that a cryptocurrency theft operation named TrapDoor is actively launching supply chain attacks in software package repositories such as npm, PyPI, and Crates.io. A total of 34 malicious packages and 384 versions and components have been identified, with attackers continuously pushing new versions across various ecosystems. TrapDoor primarily targets developers in the cryptocurrency, DeFi, AI, and security sectors, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, environment variables, and API keys. Socket detected the median time for malicious version detection to be 5 minutes and 27 seconds, with the fastest detection occurring just 58 seconds after release.
All Comments