• Trending
  • Comments
  • Latest
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
XRP community

Ripple CEO reassures community after SWIFT selects rival blockchain for pilot

02/10/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Ddsc stablecoin

Abu Dhabi’s IHC completes $30 million dirham stablecoin transfer on ADI Chain in first live institutional deployment

05/25/2026
Thorchain exploit drains up to $11 million after attackers manipulate vault churn migration process

TrapDoor malware hits 34 npm and PyPI packages to steal crypto credentials and hijack AI coding assistants

05/25/2026
Tokenized stocks

Brian Armstrong says global finance needs an overhaul and lays out eight areas blockchain and AI must fix

05/25/2026
  • Trending
  • Comments
  • Latest
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
XRP community

Ripple CEO reassures community after SWIFT selects rival blockchain for pilot

02/10/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Ddsc stablecoin

Abu Dhabi’s IHC completes $30 million dirham stablecoin transfer on ADI Chain in first live institutional deployment

05/25/2026
Thorchain exploit drains up to $11 million after attackers manipulate vault churn migration process

TrapDoor malware hits 34 npm and PyPI packages to steal crypto credentials and hijack AI coding assistants

05/25/2026
Tokenized stocks

Brian Armstrong says global finance needs an overhaul and lays out eight areas blockchain and AI must fix

05/25/2026
Monday, May 25, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

TrapDoor malware hits 34 npm and PyPI packages to steal crypto credentials and hijack AI coding assistants

Security researchers warn that a coordinated supply-chain attack is stealing wallet credentials, API keys, and cloud access from crypto and AI developers through malicious software packages.

by Joseph Samuel
43 minutes ago
in Crypto News
Reading Time: 2 mins read
0
Thorchain exploit drains up to $11 million after attackers manipulate vault churn migration process
Share on FacebookShare on Twitter

Security researchers have identified a malware campaign called TrapDoor that has spread across more than 34 malicious packages on npm, PyPI, and Rust’s Crates ecosystem, targeting crypto and AI developers to steal wallet credentials, GitHub tokens, SSH keys, and cloud access details.

According to a report published Sunday, 24th May 2026, the operation has already spread across major open-source ecosystems used by blockchain, DeFi, and artificial intelligence developers.

Malicious packages disguised as legitimate developer tools

According to Socket’s findings, the attackers disguised the malware as ordinary development utilities, including project setup tools, Solidity frameworks, AI prompt-engineering packages, and software for Move- and Sui-based blockchain applications.

The report said the campaign specifically targeted developers connected to major crypto ecosystems and platforms linked to Coinbase, Binance, MetaMask, and Brave, alongside blockchain networks such as Solana, Sui, and Aptos.

Socket researchers also warned that some of the malicious packages deployed a shared payload known as trap-core.js, which scans infected systems for credentials, validates AWS and GitHub access tokens, and attempts lateral movement using SSH-based access methods.

AI coding assistants emerge as a new attack surface

One of the more alarming elements of the campaign is its reported use of prompt injection techniques aimed at AI coding assistants.

Researchers said the attackers attempted to manipulate tools such as Claude and Cursor by embedding hidden instructions into development workflows.

According to the report, the malware pushed fake “security scan” prompts designed to trick AI tools into exposing secrets and transmitting sensitive information back to the attackers.

GitHub repositories associated with the campaign reportedly showed signs of AI-assisted malware development, including automatically generated lure repositories and partially completed malicious components.

“TrapDoor targets developers in crypto, DeFi, Solana, and AI communities,” — Socket researchers, in a published security analysis.

The disclosure comes just days after GitHub confirmed that unauthorized actors had gained access to internal repositories after compromising an employee device on May 20.

Crypto industry faces escalating supply-chain threats

The TrapDoor operation reflects a broader trend of increasingly sophisticated attacks aimed at cryptocurrency developers and infrastructure providers.

Security analysts have repeatedly warned that software supply chains and open-source ecosystems are becoming preferred entry points for attackers seeking access to wallets, private keys, and cloud environments.

The latest incident follows several high-profile malware campaigns targeting crypto users and developers through fake wallet applications, malicious browser extensions, and trojanized plugins.

Earlier research from cybersecurity firms also documented attacks that leveraged collaboration tools, fake Zoom meetings, and social engineering tactics to infiltrate crypto organizations.

For crypto investors and blockchain startups, the campaign underscores the growing operational risks tied to developer infrastructure and third-party dependencies.

With decentralized finance platforms and blockchain projects increasingly relying on open-source tooling and AI-assisted coding environments.

Cybersecurity researchers warn that attacks targeting developers could have downstream implications for wallets, smart contracts, and digital asset security.

Tags: AI coding assistantscrypto credential theftcybersecuritydeveloper toolsdigital assetsMalware Campaignnpm packagespackage compromisephishing attacksPyPI packagessoftware supply chain attackTrapDoor malware
Share196Tweet123
Joseph Samuel

Joseph Samuel

Samuel Joseph is a professional writer with experience creating clear, engaging, and well-researched crypto contents. He specializes in Crypto contents, educational articles, debate pieces, and informative reviews, with a strong ability to adapt tone to suit different audiences. With a passion for simplifying complex ideas and presenting them in a compelling way, he delivers content that informs, persuades, and connects with readers. Samuel is committed to accuracy, originality, and continuous improvement in his craft, making him a reliable voice in digital publishing.

  • Trending
  • Comments
  • Latest
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
XRP community

Ripple CEO reassures community after SWIFT selects rival blockchain for pilot

02/10/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Ddsc stablecoin

Abu Dhabi’s IHC completes $30 million dirham stablecoin transfer on ADI Chain in first live institutional deployment

05/25/2026
Thorchain exploit drains up to $11 million after attackers manipulate vault churn migration process

TrapDoor malware hits 34 npm and PyPI packages to steal crypto credentials and hijack AI coding assistants

05/25/2026
Tokenized stocks

Brian Armstrong says global finance needs an overhaul and lays out eight areas blockchain and AI must fix

05/25/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.