COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: TrapDoor malware targets 34 crypto and AI packages
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency News > TrapDoor malware targets 34 crypto and AI packages
Cryptocurrency News

TrapDoor malware targets 34 crypto and AI packages

In Brief

  • 🛑 TrapDoor malware injected 34 malicious packages into top crypto and AI platforms.

  • The attack targets tools used by Coinbase, Binance, Solana, and MetaMask.

  • Packages steal sensitive keys and exploit AI developer assistants for data leaks.

  • 🔍 Key point: $BTC developers are among the main targets of the ongoing operation.

İlayda Peker
İlayda Peker 3 weeks ago
Share
SHARE

Cybersecurity company Socket has identified a sophisticated malware campaign known as TrapDoor that has distributed dozens of malicious packages across popular developer ecosystems. This operation specifically targets software developers working in cryptocurrency and artificial intelligence projects, with findings revealing that 34 different packages and 384 versions have infiltrated major open source platforms such as npm, PyPI, and Crates.

Contents
Primary targets and affected platformsInnovative attack method exploits AI assistantsDistribution channels and detection process

Primary targets and affected platforms

The TrapDoor campaign has prioritized developers operating in technical domains including cryptocurrency wallets, cloud infrastructure management, and artificial intelligence development. Among the platforms affected are industry leaders such as Coinbase, Binance, Solana, Aptos, as well as the wallet features within MetaMask and the Brave browser.

Socket’s technical team reported that TrapDoor is engineered to target many widely used cryptocurrency wallets and is further embedded within common developer tools that communities use daily.

This malicious software is designed to steal sensitive information such as wallet credentials, SSH keys, cloud service access keys, and API authentication tokens. The infected packages are frequently integrated into developer workflows and are often downloaded without rigorous security reviews.

Innovative attack method exploits AI assistants

What sets TrapDoor apart from previous attacks is its exploitation of AI-powered developer assistants. The campaign embeds specific hidden commands within its packages to manipulate popular AI code helpers like Claude and Cursor. These commands trick the tools into conducting fake security checks while secretly transmitting sensitive data back to the attackers.

Mini glossary: Prompt injection is the manipulation of an AI model to process unexpected or harmful commands. Attackers use this tactic to make AI tools perform unintended actions or leak sensitive data.

The malicious packages often mimic legitimate and well-known developer tools by using look-alike names. For example, they imitate libraries and starter modules used in blockchain projects like Solidity, Sui, and Move, allowing attackers to infiltrate various developer communities with relative ease.

Distribution channels and detection process

TrapDoor’s operations span leading open source package platforms including npm (for JavaScript/Node.js), PyPI (for Python development), and Crates (for the Rust ecosystem). Most of the packages imitate legitimate tools and are also distributed via AI-generated fake security frameworks and bait repositories.

Socket reported an average detection time of 5 minutes and 27 seconds for malicious packages, with the fastest detection occurring in just 58 seconds. GitHub played a significant role in package distribution. Additionally, on May 20, GitHub experienced an internal cyberattack, granting unauthorized system access after an employee’s computer was compromised.

Package PlatformTargeted SectorsMain Targets
npmCryptocurrency, AICoinbase, MetaMask
PyPIData science, machine learningBinance, Solana
CratesBlockchain developmentBrave wallet

The TrapDoor malware campaign remains active, and those behind the operation have yet to be identified. Socket has refrained from attributing the incident to any specific hacking group or cybercriminal organization.

You can follow our news on Telegram, Facebook & Coinmarketcap & X
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

A sharp reversal for $XRP! Which key levels are investors watching now?

Brazil targets crypto fraud with prison terms up to 10 years

Blockworks acquires Messari in $10 million crypto data deal

Poland vetoes MiCA crypto law for the third time

XRP integrates MXNB on XRPL for US-Mexico $100B payments

İlayda Peker 25 May, 2026 - 12:45 pm 25 May, 2026 - 12:45 pm
Share This Article
Facebook Twitter
Share
İlayda Peker
By İlayda Peker
Follow:
Uluslararası İlişkiler ve Siyaset Bilimi Mezunu, Kitap sever.
Previous Article Solana holds $82 as Morgan Stanley files ETF application
Next Article Railgun (RAIL) spikes 128 percent, daily volume jumps 10x
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Dogecoin surges above $0.088 after whales buy in! What is the story behind this move?
Dogecoin (DOGE)
Transaction count on Shibarium doubles to 2600 in just four days! What does this signal for $SHIB investors?
Shiba (SHIB)
Shiba inu drops 10 as trading volume jumps 60 percent
Shiba (SHIB)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?