Related News

Analyst Explains Worst-Case Scenario for Bitcoin in 2026

Analyst Explains Worst-Case Scenario for Bitcoin in 2026

December 22, 2025
Mom of newborn left on London, Ont., porch found, police say

Mom of newborn left on London, Ont., porch found, police say

April 12, 2025

You don’t need to learn vibe coding: Build an AI ghost app in 30 mins and reclaim weeks of your life

November 15, 2025

Browse by Category

  • Canadian news feed
  • Crypto
  • Faith
  • Geothermal
  • Golf news
  • Hockey news
  • Running & fitness
  • Skateboarding
  • Sports & Fitness
  • WeMaple news

Related News

Analyst Explains Worst-Case Scenario for Bitcoin in 2026

Analyst Explains Worst-Case Scenario for Bitcoin in 2026

December 22, 2025
Mom of newborn left on London, Ont., porch found, police say

Mom of newborn left on London, Ont., porch found, police say

April 12, 2025

You don’t need to learn vibe coding: Build an AI ghost app in 30 mins and reclaim weeks of your life

November 15, 2025

Browse by Category

  • Canadian news feed
  • Crypto
  • Faith
  • Geothermal
  • Golf news
  • Hockey news
  • Running & fitness
  • Skateboarding
  • Sports & Fitness
  • WeMaple news
WEMAPLE NEWS - Brand Partnerships
  • Home
  • Canadian news feed
  • Skateboarding
  • Sports & Fitness
    • Golf
    • Hockey
    • Running & fitness
  • Faith
  • Geothermal
  • Crypto
  • WeMaple news
No Result
View All Result
CONTRIBUTE
WEMAPLE NEWS - Brand Partnerships
  • Home
  • Canadian news feed
  • Skateboarding
  • Sports & Fitness
    • Golf
    • Hockey
    • Running & fitness
  • Faith
  • Geothermal
  • Crypto
  • WeMaple news
No Result
View All Result
WEMAPLE NEWS - Brand Partnerships
No Result
View All Result
Home Crypto

Crypto Developers Under Siege As ‘TrapDoor’ Malware Hits Supply Chain

WeMaple AI by WeMaple AI
May 26, 2026
in Crypto
0
Crypto Developers Under Siege As ‘TrapDoor’ Malware Hits Supply Chain
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

The attackers behind TrapDoor went after more than wallets and passwords — they embedded hidden instructions inside packages designed to manipulate AI coding assistants.

You might also like

Whales Turn Bullish on Zcash (ZEC)—Can This Fuel the Next Price Rally?

Pi Network News: Why Pioneer’s Think Pi is ‘Dead’ Amid 10% Price Crash

Japan’s SBI Bank Expands Crypto Push With BTC, ETH, XRP Rewards Program For Depositors

According to security firm Socket, the goal was to trick tools like Claude and Cursor into running what appeared to be routine security scans, which would then quietly discover and send out secrets stored on a developer’s machine.

Socket, a developer security platform, detected the campaign on Friday and published its findings on Sunday. Reports say the operation had already pushed out more than 34 malicious packages and 384 related versions by the time it was uncovered, with attackers continuing to release new updates across multiple software ecosystems.

🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.​io.

Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems.

TrapDoor targets… pic.twitter.com/0CI758NJ6T

— Socket (@SocketSecurity) May 24, 2026

Wallets, Keys, And Cloud Credentials All At Risk

The malware cast a wide net. Socket said TrapDoor was built to steal data from several major crypto wallets — Coinbase, Binance, Solana, Sui, Aptos, and MetaMask — as well as the Brave browser. Beyond wallet data, the malware also went after SSH keys, cloud credentials, GitHub tokens, browser extension data, and API keys.

🚨 TrapDoor supply chain attack hits npm, PyPI, and Crates-io.https://t.co/Q4ZUsUnZWY

34 malicious packages across 384 versions were used to steal crypto wallets, SSH keys, cloud credentials, and developer secrets from crypto, DeFi, Solana, and AI environments.

The malware… pic.twitter.com/GJKcgUK9RK

— The Hacker News (@TheHackersNews) May 25, 2026

The campaign spread across three major developer package repositories: npm, which serves JavaScript and Node.js developers; PyPI, used widely in Python, data science, and automation work; and Crates, the package hub for Rust developers.

Package names were chosen carefully to look like standard tools — development helpers, project setup utilities, prompt engineering packages, and Solidity or Sui build helpers — making them easy to overlook during a routine install.

Socket’s chief technology officer Ahmad Nassri said on Sunday that the GitHub activity tied to the campaign showed signs of AI-assisted development, pointing to broad security-themed templates, generic lure repositories, and a mix of partially built extraction ideas alongside working malware components.

Signs Of A Larger, Coordinated Operation

The timing of the campaign raised questions given that GitHub had reported unauthorized access to its internal repositories on May 20, just days before TrapDoor was detected. That breach followed the compromise of an employee’s device, according to reports.

Socket described TrapDoor as a coordinated attack aimed squarely at crypto, decentralized finance, AI, and security developers — communities where sensitive credentials and wallet access are common.

The campaign gave attackers broad reach precisely because the targeted developer communities often work across the same tools and ecosystems.

Featured image from Unsplash, chart from TradingView

Read Entire Article
Tags: Celebrity NewsCrypto
Share30Tweet19
WeMaple AI

WeMaple AI

Recommended For You

Whales Turn Bullish on Zcash (ZEC)—Can This Fuel the Next Price Rally?

by WeMaple AI
June 10, 2026
0
Whales Turn Bullish on Zcash (ZEC)—Can This Fuel the Next Price Rally?

The post Whales Turn Bullish on Zcash (ZEC)—Can This Fuel the Next Price Rally appeared first on Coinpedia Fintech News Zcash (ZEC) price traded at around $426 at...

Read more

Pi Network News: Why Pioneer’s Think Pi is ‘Dead’ Amid 10% Price Crash

by WeMaple AI
June 10, 2026
0
Pi Network News: Why Pioneer’s Think Pi is ‘Dead’ Amid 10% Price Crash

The post Pi Network News: Why Pioneer’s Think Pi is ‘Dead’ Amid 10% Price Crash appeared first on Coinpedia Fintech News Pi Network is once again under fire...

Read more

Japan’s SBI Bank Expands Crypto Push With BTC, ETH, XRP Rewards Program For Depositors

by WeMaple AI
June 10, 2026
0
Japan’s SBI Bank Expands Crypto Push With BTC, ETH, XRP Rewards Program For Depositors

The banking arm of Japanese financial giant SBI Holdings is reportedly launching a crypto rewards program for depositors as part of a broader push to expand its digital...

Read more

XRP Being Suppressed? Researcher Reveals Why The Token Isn’t Soaring

by WeMaple AI
June 10, 2026
0
XRP Being Suppressed? Researcher Reveals Why The Token Isn’t Soaring

A 2021 Citibank document that used the phrase “Regulated Internet of Value” sits at the center of a new XRP debate, after researcher Jesse of Apex Crypto Insights...

Read more

CLARITY Act momentum slows to a crawl as lawmakers clash over crypto ethics rules

by WeMaple AI
June 10, 2026
0

Bipartisan Senate talks over crypto ethics turned rocky this week after a Democratic source described an “about-face” by GOP members and the White House on a prior enforcement...

Read more
Next Post
Why Is Render Price Up Today?

Why Is Render Price Up Today?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Analyst Explains Worst-Case Scenario for Bitcoin in 2026

Analyst Explains Worst-Case Scenario for Bitcoin in 2026

December 22, 2025
Mom of newborn left on London, Ont., porch found, police say

Mom of newborn left on London, Ont., porch found, police say

April 12, 2025

You don’t need to learn vibe coding: Build an AI ghost app in 30 mins and reclaim weeks of your life

November 15, 2025

Browse by Category

  • Canadian news feed
  • Crypto
  • Faith
  • Geothermal
  • Golf news
  • Hockey news
  • Running & fitness
  • Skateboarding
  • Sports & Fitness
  • WeMaple news
WEMAPLE NEWS – Brand Partnerships

Wemaple will be firmly committed to the public interest and democratic values.

CATEGORIES

  • Canadian news feed
  • Crypto
  • Faith
  • Geothermal
  • Golf news
  • Hockey news
  • Running & fitness
  • Skateboarding
  • Sports & Fitness
  • WeMaple news

BROWSE BY TAG

AZO Clean Tech Bitcoinist Bitcoinmagazine Canada News CBC.ca Celebrity News Christian Post CoinPedia Corporate Knights Crypto Cryptoslate Faith Geothermal Golf Hockey Lifehacker Ludwig-van.com NcrOnline newsbtc Skateboarding tomsguide.com Utah news dispatch

© 2025 wemaple.canadiana.news - all rights reserved. YYC TECH CONSULTING.

No Result
View All Result
  • Home
  • Canadian news feed
  • Skateboarding
  • Sports & Fitness
    • Golf
    • Hockey
    • Running & fitness
  • Faith
  • Geothermal
  • Crypto
  • WeMaple news

© 2025 wemaple.canadiana.news - all rights reserved. YYC TECH CONSULTING.