The developer ecosystem is facing a sophisticated new threat dubbed “TrapDoor,” a coordinated supply chain campaign that has compromised over 34 malicious packages across three major registries: npm, PyPI, and Crates.io. This attack is not merely a simple credential stealer; it is a calculated operation targeting the most sensitive segments of the modern development stack, specifically focusing on AI researchers and Web3/DeFi developers.
The Multi-Vector Execution Strategy
TrapDoor is notable for its ecosystem-specific delivery methods, ensuring that the malware executes silently regardless of the language environment:
1. npm (JavaScript/TypeScript)
The attack utilizes postinstall hooks to deploy a shared payload called trap-core.js. Once active, this script performs a comprehensive scan for AWS and GitHub tokens, validating them via API calls before exfiltration. It also attempts lateral movement via SSH and establishes persistence through systemd, cron, and surprisingly, AI configuration files like .cursorrules and CLAUDE.md.
2. PyPI (Python)
The Python implementation employs a more dynamic approach. Upon import, the malicious package downloads a remote JavaScript payload from attacker-controlled GitHub Pages. This allows the threat actors to update the malware behavior in real-time without having to publish new versions to PyPI, effectively bypassing many static analysis tools.
3. Crates.io (Rust)
Targeting the high-performance world of Rust, TrapDoor leverages malicious build.rs scripts. These scripts execute during the compilation phase, specifically hunting for Sui and Move developer keystores. The stolen data is XOR-encrypted using the key cargo-build-helper-2026 before being uploaded to GitHub Gists.
The AI Angle: Weaponizing AI Tooling
Perhaps the most alarming aspect of TrapDoor is its attempt to exploit AI-powered coding assistants. Attackers have been found injecting hidden instructions—sometimes utilizing zero-width Unicode characters—into .cursorrules and CLAUDE.md files.
By manipulating these files, the malware tricks AI agents (like Cursor or Claude) into performing tasks under the guise of “security scans.” These AI-driven workflows are then used to uncover and exfiltrate secrets that a traditional script might have missed, marking a new frontier in social engineering where the “victim” is the AI assistant itself.
Impact and Mitigation
The campaign specifically targets cryptocurrency wallets (Sui, Solana, Aptos), SSH keys, and cloud credentials. With a median detection time of only 5 minutes and 27 seconds, the window for reaction is incredibly small.
To protect your environment, we recommend:
- Strict Dependency Auditing: Use tools like
npm auditorpip-audit, but complement them with behavioral analysis tools. - Secret Management: Move away from
.envfiles and hardcoded keys toward dedicated secret managers (e.g., HashiCorp Vault, AWS Secrets Manager). - AI Config Hygiene: Be wary of any automatically generated or third-party
.cursorrulesorCLAUDE.mdfiles in your repositories. - Credential Rotation: If you have installed any packages claiming to be “security auditors” or “performance helpers” since May 2026, rotate your API keys and SSH credentials immediately.