Home TrapDoor Malware Attack Targets Crypto Developers Across npm, PyPI & Crates.io

TrapDoor Malware Attack Targets Crypto Developers Across npm, PyPI & Crates.io

Share
TrapDoor Malware Attack Targets Crypto Developers Across npm, PyPI & Crates.io
News
Share

A large malware attack called TrapDoor is targeting crypto developers through harmful packages uploaded on npm, PyPI, and Crates.io, according to cybersecurity firm Socket.

Researchers found 34 harmful packages and hundreds of infected versions made to steal crypto wallet data, SSH keys, API credentials, GitHub tokens, and cloud access info. The attack specifically targets developers working in crypto, DeFi, Solana, AI, and blockchain systems.

The harmful packages were disguised as normal development tools with names like “wallet-security-checker,” “defi-env-auditor,” and “cryptowallet-safety.”

Some packages ran malicious code automatically during installation, while others used Rust build scripts or Python imports to trigger hidden attacks.

Socket warned that the malware also tries to trick AI coding assistants by hiding harmful instructions inside .cursorrules and CLAUDE.md files using invisible Unicode characters.

Security researchers called the campaign one of the most advanced crypto-focused software supply-chain attacks to date. Developers who installed any affected packages have been told to immediately change passwords, replace SSH keys, check Git hooks and system services, and inspect development setups for unauthorized access.

The incident highlights the growing cybersecurity risks facing the crypto and AI development world, as attackers increasingly combine malware, open-source software, and AI trickery.

Share
Written by
Kapil Rajyaguru -

Kapil Rajyaguru is a news editor at 3.0 TV with over 15 years of professional writing experience and more than four years dedicated to the cryptoverse.

An engineer by education and a writer by passion, Kapil brings a rare mix of technical insight and storytelling finesse. A firm believer that cryptocurrencies, blockchain and AI are the building blocks of the future, he crafts in-depth news and analysis to educate, empower and prepare the masses for the next frontier of Web3.

Leave a comment

Leave a Reply

Latest News

Can Coinhouse Lead Europe’s Crypto Expansion After Winning Full MiCA Licence?
News

Can Coinhouse Lead Europe’s Crypto Expansion After Winning Full MiCA Licence?

Coinhouse’s full MiCA licence is an important move toward the expansion of regulated cryptocurrency in Europe. With clearance from France’s AMF, the...

Who Was Nathan Allman? Ondo Finance Founder Dies Unexpectedly At 32
News

Who Was Nathan Allman? Ondo Finance Founder Dies Unexpectedly At 32

The cryptocurrency and blockchain industries are shocked by the sudden death of Nathan Allman, the founder and CEO of Ondo Finance, at...

TrapDoor Malware Attack Targets Crypto Developers Across npm, PyPI & Crates.io
News

TrapDoor Malware Attack Targets Crypto Developers Across npm, PyPI & Crates.io

A large malware attack called TrapDoor is targeting crypto developers through harmful packages uploaded on npm, PyPI, and Crates.io, according to cybersecurity...

Hyperliquid Expands Beyond Crypto Trading, Challenges Traditional Exchanges
News

Hyperliquid Expands Beyond Crypto Trading, Challenges Traditional Exchanges

Decentralized trading platform Hyperliquid is quickly expanding beyond crypto perpetual futures and beginning to compete with traditional exchanges and prediction market operators,...

Latest Blogs

How To Spot The Next Big Memecoin

Inspired by online jokes and viral trends, memecoins are the not-so-serious and rather amusing part of digital coins that thrive on community...

AI & Web3: New Age Careers With High Income Potential?

The smartest move going forward right now is to build a career in next generation internet, AI and Web3. The good news...

Art Of Becoming A Memecoin Master & Staying Ahead

Within the cryptocurrency market, memecoins are a more lighthearted and entertaining segment. They are created from online comedy, viral trends, and jokes....

“Click, Token, Own!” Why RWA Is The Future Of Finance?

A financial revolution, RWA tokenization bringing real-world assets onto blockchain RWA tokenization increases accessibility, quickness and transparency, pushing markets to expand rapidly,...

Related Articles

How To Spot The Next Big Memecoin

Inspired by online jokes and viral trends, memecoins are the not-so-serious and...

AI & Web3: New Age Careers With High Income Potential?

The smartest move going forward right now is to build a career...

Art Of Becoming A Memecoin Master & Staying Ahead

Within the cryptocurrency market, memecoins are a more lighthearted and entertaining segment....

“Click, Token, Own!” Why RWA Is The Future Of Finance?

A financial revolution, RWA tokenization bringing real-world assets onto blockchain RWA tokenization...