COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: TrapDoor malware targets 34 crypto and AI packages
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency News > TrapDoor malware targets 34 crypto and AI packages
Cryptocurrency News

TrapDoor malware targets 34 crypto and AI packages

In Brief

  • 🛑 TrapDoor malware injected 34 malicious packages into top crypto and AI platforms.

  • The attack targets tools used by Coinbase, Binance, Solana, and MetaMask.

  • Packages steal sensitive keys and exploit AI developer assistants for data leaks.

  • 🔍 Key point: $BTC developers are among the main targets of the ongoing operation.

İlayda Peker
İlayda Peker 43 minutes ago
Share
SHARE

Cybersecurity company Socket has identified a sophisticated malware campaign known as TrapDoor that has distributed dozens of malicious packages across popular developer ecosystems. This operation specifically targets software developers working in cryptocurrency and artificial intelligence projects, with findings revealing that 34 different packages and 384 versions have infiltrated major open source platforms such as npm, PyPI, and Crates.

Contents
Primary targets and affected platformsInnovative attack method exploits AI assistantsDistribution channels and detection process

Primary targets and affected platforms

The TrapDoor campaign has prioritized developers operating in technical domains including cryptocurrency wallets, cloud infrastructure management, and artificial intelligence development. Among the platforms affected are industry leaders such as Coinbase, Binance, Solana, Aptos, as well as the wallet features within MetaMask and the Brave browser.

Socket’s technical team reported that TrapDoor is engineered to target many widely used cryptocurrency wallets and is further embedded within common developer tools that communities use daily.

This malicious software is designed to steal sensitive information such as wallet credentials, SSH keys, cloud service access keys, and API authentication tokens. The infected packages are frequently integrated into developer workflows and are often downloaded without rigorous security reviews.

Innovative attack method exploits AI assistants

What sets TrapDoor apart from previous attacks is its exploitation of AI-powered developer assistants. The campaign embeds specific hidden commands within its packages to manipulate popular AI code helpers like Claude and Cursor. These commands trick the tools into conducting fake security checks while secretly transmitting sensitive data back to the attackers.

Mini glossary: Prompt injection is the manipulation of an AI model to process unexpected or harmful commands. Attackers use this tactic to make AI tools perform unintended actions or leak sensitive data.

The malicious packages often mimic legitimate and well-known developer tools by using look-alike names. For example, they imitate libraries and starter modules used in blockchain projects like Solidity, Sui, and Move, allowing attackers to infiltrate various developer communities with relative ease.

Distribution channels and detection process

TrapDoor’s operations span leading open source package platforms including npm (for JavaScript/Node.js), PyPI (for Python development), and Crates (for the Rust ecosystem). Most of the packages imitate legitimate tools and are also distributed via AI-generated fake security frameworks and bait repositories.

Socket reported an average detection time of 5 minutes and 27 seconds for malicious packages, with the fastest detection occurring in just 58 seconds. GitHub played a significant role in package distribution. Additionally, on May 20, GitHub experienced an internal cyberattack, granting unauthorized system access after an employee’s computer was compromised.

Package PlatformTargeted SectorsMain Targets
npmCryptocurrency, AICoinbase, MetaMask
PyPIData science, machine learningBinance, Solana
CratesBlockchain developmentBrave wallet

The TrapDoor malware campaign remains active, and those behind the operation have yet to be identified. Socket has refrained from attributing the incident to any specific hacking group or cybercriminal organization.

You can follow our news on Telegram, Facebook & Coinmarketcap & X
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

Railgun (RAIL) spikes 128 percent, daily volume jumps 10x

AI agents make 176 million blockchain payments worth $73 million

BlackRock CEO urges SEC to speed up token approvals

Kuantum and AI threaten blockchain, ETH and XRP at risk

Clarity act vote delayed again as US Congress stalls

İlayda Peker 25 May, 2026 - 12:45 pm 25 May, 2026 - 12:45 pm
Share This Article
Facebook Twitter
Share
İlayda Peker
By İlayda Peker
Follow:
Uluslararası İlişkiler ve Siyaset Bilimi Mezunu, Kitap sever.
Previous Article Solana holds $82 as Morgan Stanley files ETF application
Next Article Railgun (RAIL) spikes 128 percent, daily volume jumps 10x
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Bitcoin eyes PCE inflation data as $81,000 resistance looms
Bitcoin (BTC)
Railgun (RAIL) spikes 128 percent, daily volume jumps 10x
Cryptocurrency News
Solana holds $82 as Morgan Stanley files ETF application
Solana (SOL)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?