Socket researchers have uncovered TrapDoor, an active supply chain attack spanning 34+ malicious packages across npm, PyPI, and Crates.io. The campaign targets crypto, DeFi, Solana, and AI developers, stealing SSH keys, crypto wallet data, AWS credentials, GitHub tokens, browser data, and environment variables. npm packages use postinstall hooks to deploy a 1,149-line credential harvester (trap-core.js) with persistence via .cursorrules, CLAUDE.md, Git hooks, systemd, and cron. PyPI packages execute remote JavaScript on import, while Crates.io packages abuse build.rs scripts to exfiltrate keystores via GitHub Gists. A novel feature involves injecting hidden Unicode instructions into AI coding tool config files (.cursorrules, CLAUDE.md) to trick AI assistants into running fake 'security scans' that exfiltrate data. The attacker also opened PRs against major open source AI projects (LangChain, LlamaIndex, MetaGPT) to plant malicious config files. Socket detected packages in under 6 minutes on average and has reported all identified packages to affected registries.

11m read timeFrom socket.dev
Post cover image
Table of contents
npm Packages #PyPI Packages #Crates.io Packages #A Coordinated Cross-Ecosystem Campaign #What TrapDoor Steals #npm Packages Use Postinstall Hooks and Persistent Credential Harvesting #Crates.io Packages Exfiltrate Wallet Keystores #PyPI Packages Execute Remote JavaScript on Import #AI Injection Targets Developer Assistants #Encryption and Credential Validation #Attacker Playbook Found in GitHub Pages Repo #Attacker Opens PRs to AI and Developer Projects #Low-Volume Packages, High-Value Targets #Socket Detection #Indicators of Compromise #
847 Impressions