TrapDoor Malware Hits 34 Packages Targeting Crypto Wallets and AI Tools
Security researchers on May 25 disclosed an active supply-chain attack deploying TrapDoor malware across npm, PyPI and Crates.io. The campaign has already published 34 malicious packages in 384 versions that steal MetaMask, Phantom, Coinbase and Binance credentials along with SSH keys and GitHub tokens. Attackers also inject hidden prompts into AI coding assistants to exfiltrate secrets, compounding recent unauthorized GitHub access reported May 20. The incident raises custody and operational risks for Bitcoin and other crypto projects while prompting urgent calls for stricter package verification and hardware-wallet use.