Scan to download
BTC $76,964.28 +0.31%
ETH $2,091.37 -1.33%
BNB $656.24 -0.04%
XRP $1.35 -1.03%
SOL $84.92 -1.17%
TRX $0.3643 +0.38%
DOGE $0.1018 -0.97%
ADA $0.2406 -1.91%
BCH $345.03 -2.78%
LINK $9.39 -1.58%
HYPE $61.66 +2.22%
AAVE $85.41 -0.80%
SUI $1.02 -3.87%
XLM $0.1471 -0.76%
ZEC $652.03 +2.66%
BTC $76,964.28 +0.31%
ETH $2,091.37 -1.33%
BNB $656.24 -0.04%
XRP $1.35 -1.03%
SOL $84.92 -1.17%
TRX $0.3643 +0.38%
DOGE $0.1018 -0.97%
ADA $0.2406 -1.91%
BCH $345.03 -2.78%
LINK $9.39 -1.58%
HYPE $61.66 +2.22%
AAVE $85.41 -0.80%
SUI $1.02 -3.87%
XLM $0.1471 -0.76%
ZEC $652.03 +2.66%

The cryptocurrency theft program TrapDoor is attacking three major code repositories, with 34 malicious software packages detected

2026-05-25 09:36:56
Collection

Security company Socket Security disclosed that a cryptocurrency theft operation named TrapDoor is launching active supply chain attacks in package repositories such as npm, PyPI, and Crates.io. A total of 34 malicious packages and 384 versions and components have been identified, with attackers continuously pushing new versions across various ecosystems.

TrapDoor primarily targets developers in the cryptocurrency, DeFi, AI, and security fields, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, environment variables, and API keys. Socket detected that the median detection time for malicious versions was 5 minutes and 27 seconds, with the fastest detection occurring 58 seconds after release.

app_icon
ChainCatcher Building the Web3 world with innovations.