Skip to main content
Featured AnalysisPrimary topicInfrastructure

TrapDoor campaign plants 34 poisoned npm, PyPI and Crates packages to steal wallets, SSH keys and API tokens

Security firm Socket uncovered a supply‑chain malware operation called "TrapDoor" that distributed 34 compromised packages across npm, PyPI and Crates to target crypto and AI developer tooling [1][2].

May 25, 20269:00 AMNewsroom AI

Researchers at Socket identified a sophisticated campaign named TrapDoor that placed 34 compromised packages in popular developer repositories including npm, PyPI and Crates, enabling the malware to reach developer supply chains via poisoned packages [1] [2].

The operation specifically targeted developers working on cryptocurrency, decentralized finance, artificial intelligence and cybersecurity projects and was designed to harvest wallet data, SSH credentials, cloud access tokens and API authentication keys; reported targets and integrations of interest include Coinbase, Binance, Solana, MetaMask and Brave wallet functionality [1] [2] [3].

The campaign has been covered across security outlets and community forums following Socket's disclosure, with ongoing analysis of the 34 identified malicious packages and their distribution vectors reported by multiple outlets [1] [4] [3].

Was this useful?

Anonymous signal used only for weekly cluster rankings. No public counters.

Share

Broadcast this coverage

Copy-ready links for the networks your audience checks first.

Support independent reporting

If this summary helped, a small tip helps keep ClusterWire running.

Privacy note: we log tip UI events (page + action, and article slug when applicable) to improve the feature. We don’t store IP address, user-agent, or wallet addresses in analytics. Tips are on-chain, so the sending address is public in the transaction.

Source Ledger

Citations

Follow the primary reporting behind this analysis. Click a citation to open the referenced source in a new tab.

Themes

Themes driving this story

Curated from the cluster of sources powering this article.

DeFiThemeAltcoinsThemeEthereumThemeExchanges/CustodyThemeBitcoinTheme
Live Wire

Latest Coverage

Real-time crypto intelligence ordered by publication time.

1h ago

Hungary reverses parts of 2025 crypto limits, easing conversion and ending trading penalties

Hungary has moved to reverse parts of its 2025-era restrictions on cryptocurrency conversions and trading. Separate reports say the government is undoing conversion limitations …

Read more
23h ago

Bitcoin’s Overwater Supply Surge Meets DXY Compression and CPI Volatility Risks

More than half of Bitcoin’s circulating supply is now “underwater,” meaning it is trading below the price investors paid when they acquired it. The report links the shift to BTC…

Read more
23h ago

Solana becomes WSOP 2026 sponsor, enabling SOL and stablecoin buy-in payments

Solana has become the official presenting sponsor of the World Series of Poker (WSOP) 2026, with the event promoting the ability for players to enter tournaments using crypto on…

Read more
26h ago

Polychain-Backed Botanix Will Shut Down Bitcoin Layer 2, Users Urged to Withdraw by July 9

Botanix Labs has announced it will wind down its Bitcoin Layer 2 network, telling users to withdraw remaining assets. Multiple reports say the company warned users to move funds…

Read more
27h ago

Whales Accumulate 200M DOGE as Derivatives Sentiment Turns and MoonPay Expands Payments

Dogecoin (DOGE) rebounded as large holders accumulated about 200 million DOGE tokens over the past week, according to on-chain and analytics referenced by multiple reports. One …

Read more
28h ago

Bitcoin Slumps on Iran-CPI Turmoil, Tests Key Levels as Bulls Cite Discounted Value

Bitcoin’s price action in early June has been marked by a sharp selloff amid geopolitical tensions. Reports say BTC logged its worst weekly loss since the 2022 FTX collapse, dro…

Read more