• Advertise with us
  • Pricing
  • Submit News
Instagram Twitter Facebook Telegram Youtube Linkedin
EdaFace Newsfeed
EdaFace Newsfeed
  • News

    Main News

    • Crypto News
    • Bitcoin and BTC
    • Altcoin News
    • Security & Hacks
    • ICO & Token Sales
    • Interviews & Profiles

    Information

    • Press Release
    • Research Report
    • Regulations, Law & Policy
    • Community/Guest Post
    • Events & Conferences
    • Tutorials & Guides

    Market

    • Technical Analysis
    • Price Analysis
    • Cryptocurrency Price Prediction
    • DeFi (Decentralized Finance)
    • Mining & Staking

    Other Categories

    • NFTs & Digital Art
    • Opinion & Editorials
    • Tech Innovations
  • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
More
  • News
  • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
Reading: TrapDoor malware operation leaked 34 malicious packages to developer platforms
Share
Sign In
EdaFace Newsfeed
EdaFace Newsfeed
  • EdaFace Home
  • Edaface News
    • EdaFace News
    • Advertisement
    • Pricing
    • Submit News
  • News
    • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
  • Contact Us
  • EdaFace Home
  • Edaface News
    • EdaFace News
    • Advertisement
    • Pricing
    • Submit News
  • News
    • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
  • Contact Us
EdaFace Newsfeed > Latest News > Crypto News > TrapDoor malware operation leaked 34 malicious packages to developer platforms
Crypto News

TrapDoor malware operation leaked 34 malicious packages to developer platforms

vitalclick
Last updated: May 25, 2026 9:24 am
6 hours ago
Share
SHARE

Contents
Targeted sectors and platformsInnovative attack techniqueDistribution channels and detection process

According to findings by cybersecurity firm Socket, a sophisticated malware operation called TrapDoor distributed dozens of malicious packages in package ecosystems frequently used by software developers. This operation, which specifically targeted developers working on cryptocurrency and artificial intelligence projects, revealed that 34 different packages and 384 versions were spread across popular open source platforms such as npm, PyPI and Crates.

Targeted sectors and platforms

The TrapDoor attack specifically prioritized developers working in technical fields such as cryptocurrency wallets, cloud infrastructure management and artificial intelligence development. Among the platforms attacked were Coinbase, Binance, Solana, Aptos and MetaMask, which are among the leading names in the market, and the wallet feature of the Brave browser.

Socket’s technical team stated that TrapDoor was designed to target many well-known cryptocurrency wallets and has additionally spread into the tools that developer communities use daily.

The malware captures sensitive data such as wallet information, SSH keys, access keys to cloud services, and API authorization keys. These packages, which are frequently included in workflows in developer interfaces, are often downloaded without being subjected to detailed security review.

Innovative attack technique

The most striking aspect that distinguishes TrapDoor from similar attacks is the manipulation of artificial intelligence-supported developer assistants. In particular, special commands hidden inside the packages were placed to mislead popular artificial intelligence coding tools such as Claude and Cursor. While these commands enable software assistants to perform a so-called security assessment, they also transmit sensitive information to attackers in the background.

Mini dictionary: Prompt injection is the manipulation of the model in artificial intelligence applications to receive unexpected or harmful commands. With this method, attackers can force AI tools to perform actions other than the original intent or send confidential data.

Malicious packages are similar in name to legitimate and common developer tools. It is offered with names that mimic the libraries and starter modules used in blockchain projects such as Solidity, Sui and Move. It is stated that thanks to this strategy, attackers can easily infiltrate different developer communities.

Distribution channels and detection process

The TrapDoor operation is spread across major open source package platforms such as npm (JavaScript/Node.js), PyPI (Python development) and Crates (Rust ecosystem). While most packages mimic legitimate tools; It is emphasized that it is also distributed through fake security frameworks and decoy repositories, which are thought to be prepared with the support of artificial intelligence.

Socket stated that a malicious package was detected in an average of 5 minutes and 27 seconds, and the fastest detection occurred in only 58 seconds. GitHub in particular played an important role in the distribution. Additionally, on May 20, it was reported that GitHub experienced an independent cyberattack within the company, allowing unauthorized access to systems by compromising an employee’s computer.

Package Platform Targeted Sectors Most Known Targets
npm Cryptocurrency, artificial intelligence Coinbase, MetaMask
PyPI Data science, machine learning Binance, Solana
Crates Blockchain development brave wallet

The TrapDoor attack campaign is still active and the perpetrators have not been identified. Socket did not directly attribute responsibility for the incident to any hacking group or cybercrime organization.

Disclaimer: The information contained in this content is not investment advice. Please note that cryptocurrencies involve high volatility and therefore risk. It is recommended that you make your investment decisions based on your own research and risk assessments. You can review our Trust Center page for detailed information.

You Might Also Like

Senator Tillis Commits to May 11 Markup Push as Final Talks Intensify

Behind Solana and Ripple’s One-Word ‘XRP’ Posts Lies a Real $100 Million Integration

YouTube Now Lets U.S. Creators Get Paid in PayPal’s PYUSD Stablecoin

Hard Brake on Cryptocurrency: 100 Percent Risk Bomb

Will XRP’s Secondary Sales Determine the Future of Crypto Regulation?

TAGGED:Cryptocurrency
Share This Article
Facebook Twitter Email Print
Previous Article Critical support fight in Solana, Morgan Stanley presents updated ETF application
Next Article RAIL approached its peak in 2026, transaction volume increased 10 times
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Crypto Live Widget

Follow for Live Updates
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad imageAd image
Popular News
Why Ethereum is Poised to Explode to $4,600 Sooner Than You Think!
Five Altcoins With 100x Potential To Buy Now
ETF Approvals, Regulatory Frameworks, and Market Dynamics
Top News, Bitcoin and Altcoin Volatility, Major Hacks, and DeFi Investments
RCO Finance (RCOF) Captures The Future

Company

  • Vision
  • Mission
  • LitePaper
  • Whitepaper
  • Core Values
  • Branding
  • Teams
  • Career Listing
  • FAQ
  • Welfare Donations

Products

  • EDA Coin
  • Blockchain Literature
  • EdaFace Dex
  • EdaFace Mall
  • Listing Platforms
  • Newsfeed
  • NFT Marketplace
  • P2P Market
  • Scam Verification Centre
  • School of Crypto

Legal

  • Term of Use
  • Privacy Policy
  • Disclaimers
  • Contact Us
  • Chat Forun

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

EdaFace

About US

EdaFace is a user interface aggregator that brings all the various functionalities of the crypto industry onto a single platform! You can advertise, launch and crowdfund your crypto project via EdaFace Launchpad and Newsfeed.

Contact us: [email protected]

Follow us

Instagram Twitter Facebook Telegram Youtube Linkedin

Copyright © 2022 – 2026. EdaFace is a product of Emerging Digital Age (EDA) Pty Ltd. All Rights Reserved.

Join Us!
Subscribe to our newsletter and never miss our latest news, podcasts etc..

Zero spam, Unsubscribe at any time.
EdaFace
Welcome Back!

Sign in to your account

Lost your password?