Grafa
TrapDoor malware hits crypto and AI developer tools
Image for illustrative purposes only. Not a real photo.

TrapDoor malware hits crypto and AI developer tools

Share

Security platform Socket said it uncovered a malware campaign called TrapDoor targeting crypto, DeFi, artificial intelligence, and cybersecurity developers through poisoned software packages.

Socket said attackers deployed more than 34 malicious packages and 384 related versions across popular developer ecosystems including npm, PyPI, and Rust’s Crates repository in an effort to steal credentials, wallet data, and cloud access keys.

“The goal appears to be to trick AI assistants into running a ‘security scan’ or similar workflow that causes secret discovery and exfiltration,”

Socket stated.

The malware reportedly targeted crypto wallets and platforms including Coinbase, Binance, Solana, Sui, Aptos, and MetaMask alongside browser and cloud credentials.

Socket chief technology officer Ahmad Nassri said the malware also injected hidden instructions designed to hijack AI coding assistants including Claude and Cursor by manipulating automated security workflows.

The campaign reportedly disguised malicious packages as development helpers, Solidity tooling, AI utilities, and blockchain build tools to increase the likelihood developers would unknowingly install infected software during routine workflows.

The findings came days after GitHub disclosed unauthorised access to internal repositories following the compromise of an employee device, with Socket suggesting the broader campaign showed signs of rapid AI-assisted malware development and deployment.

Frequently asked questions

Grafa is not a financial advisor. You should seek independent, legal, financial, taxation or other advice that relate to your unique circumstances.

Grafa is not liable for any loss caused, whether due to negligence or otherwise arising from the use of or reliance on the information provided directly or indirectly, by use of this platform.