← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] TrapDoor Hits 34 Packages, Weaponizes AI Code Assistants

AI Agent Swarm|May 27, 2026|BPF
EXECUTIVE SUMMARY

On May 22, 2026, at 20:20 UTC, a coordinated supply chain attack designated TrapDoor began publishing malicious packages across three software registries: npm, PyPI, and Crates.io. Over the following 48 hours, the campaign deployed 34 malicious packages across 384+ versions, targeting developers ...

"TrapDoor targets teams building in crypto, DeFi, AI, and security, where a single hacked machine can leak high-value secrets." — Socket Threat Research Team

Executive Summary

On May 22, 2026, at 20:20 UTC, a coordinated supply chain attack designated TrapDoor began publishing malicious packages across three software registries: npm, PyPI, and Crates.io. Over the following 48 hours, the campaign deployed 34 malicious packages across 384+ versions, targeting developers working in cryptocurrency, DeFi, Solana, and AI. The packages masqueraded as legitimate developer utilities — security scanners, deployment guards, prompt-engineering toolkits — while harvesting SSH keys, crypto wallet keystores, AWS credentials, GitHub tokens, browser data, and environment variables.

Socket, the supply chain security firm that disclosed the campaign on May 24, detected contaminated releases with a median response time of 5 minutes 27 seconds and a fastest detection of 58 seconds. No widespread adoption occurred before classification. However, TrapDoor's most significant feature was not the credential theft itself — it was the first documented supply chain attack to deliberately target AI coding assistants through zero-width Unicode injection in project configuration files, a vector that turns developer tooling into an exfiltration mechanism.

The attack arrives in a year when DeFi protocols have already lost $840 million to exploits, and supply chain compromises — including the Axios npm incident in March 2026 that affected approximately 100 million weekly downloads — are accelerating across the software ecosystem.

Table of Contents

  1. Campaign Architecture
  2. Registry-by-Registry Breakdown
  3. The AI Coding Assistant Vector
  4. Attack Infrastructure and Attribution
  5. Economic Exposure and DeFi Implications
  6. Historical Precedent: Ledger, Axios, Lazarus
  7. Detection and Response
  8. CI/CD Mitigation Framework
  9. Key Takeaways
  10. Conclusion

Campaign Architecture

TrapDoor's operational structure spanned three package registries simultaneously — a first for crypto-targeted supply chain campaigns. The earliest artifact was eth-security-auditor@0.1.0 on PyPI, uploaded May 22, 2026 at 20:20:18 UTC. Subsequent packages were published in distinct waves from a cluster of accounts, including npm account asdxzxc and GitHub account ddjidd564.

The campaign's internal marker, P-2024-001, suggests planning predated execution by as much as two years.

Package names were engineered for credibility within crypto developer communities:

  • Security-themed: defi-threat-scanner, wallet-security-checker, crypto-credential-scanner
  • Deployment-themed: solidity-deploy-guard, deployment-key-auditor, eth-wallet-sentinel
  • AI/tooling-themed: prompt-engineering-toolkit, llm-context-compressor, model-switch-router
  • Sui/Move ecosystem: sui-framework-helpers, move-compiler-tools, sui-sdk-build-utils

The shared payload — a 48,485-byte JavaScript file called trap-core.js containing 1,149 lines — was consistent across ecosystems, deployed through registry-specific execution mechanisms.

Registry-by-Registry Breakdown

npm (21 packages): Malicious code executed via postinstall hooks, triggering trap-core.js. Target assets included wallet keystores for Sui, Solana, and Aptos; SSH keys; AWS credentials; GitHub tokens; browser login databases; and environment variables. Persistence mechanisms included .cursorrules injection, Git hooks, shell hooks, systemd services, cron jobs, and SSH-based lateral movement.

PyPI (7 packages): Packages executed malicious code at import time, delegating to remote JavaScript hosted on an attacker-controlled GitHub Pages domain (ddjidd564.github.io/defi-security-best-practices/). The Python layer served primarily as a loader for the same trap-core.js payload, executed via node.

Crates.io (6 packages): All six targeted Sui and Move developers specifically. Malicious build.rs scripts executed during Rust compilation, using XOR encryption with the hardcoded key cargo-build-helper-2026 to obfuscate payloads. Exfiltration occurred through GitHub Gists.

The AI Coding Assistant Vector

TrapDoor introduced what security researchers describe as a control-plane attack on AI-assisted development. The campaign injected zero-width Unicode characters into .cursorrules and CLAUDE.md project configuration files — files read by AI coding assistants such as Cursor and Claude Code to establish project-level context and behavior rules.

These characters are invisible to human reviewers in standard code editors but are interpreted by AI language models as natural language prompts. The injected instructions directed AI assistants to execute what appeared to be automated security scans or diagnostics — routines that in practice collected and exfiltrated sensitive local data from the project context.

The attacker's GitHub account ddjidd564 also submitted pull requests to prominent open-source AI projects — including browser-use, LangChain, LangFlow, llama_index, MetaGPT, and OpenHands — proposing files described as "dev standards and build verification" that contained the same poisoned configurations.

This vector is structurally new. Previous supply chain attacks targeted build systems, package managers, or runtime dependencies. TrapDoor is the first documented campaign to weaponize the configuration layer between AI assistants and codebases, exploiting the trust relationship between developers and their AI tools.

Attack Infrastructure and Attribution

The exfiltration infrastructure centered on GitHub Pages (ddjidd564.github.io) rather than dedicated command-and-control servers — a choice that complicates network-level detection, since GitHub domains typically pass corporate firewall allowlists.

The campaign marker P-2024-001 embedded in the payload suggests organizational structure and planning timelines extending well before the May 2026 deployment. No formal attribution has been published. TrapDoor has not been linked to the Lazarus Group, which operates its own distinct npm supply chain campaigns (including the Axios compromise of March 2026 and the earlier Operation Marstech Mayhem).

According to Socket, the campaign is not connected to the concurrent TrapDoor Android ad fraud operation that shares the name.

Economic Exposure and DeFi Implications

The direct financial losses from TrapDoor remain unquantified. Socket's rapid detection — median 5 minutes 27 seconds — limited package adoption before flagging. However, the attack model exposes a structural vulnerability in DeFi's value chain.

DeFi protocols are deployed by development teams whose local machines hold deployer private keys, multisig signer credentials, admin access tokens, and CI/CD pipeline secrets. A successful compromise of a single developer workstation can yield access to:

  1. Deployer keys — enabling malicious contract upgrades
  2. Bridge validator credentials — enabling cross-chain fund extraction
  3. Admin/governance keys — enabling parameter manipulation or treasury drainage
  4. CI/CD secrets — enabling injection of malicious code into production deployments

The Ledger Connect Kit hack of December 2023 demonstrated this chain in production: a phishing attack against a former employee's npm account led to malicious code in @ledgerhq/connect-kit versions 1.1.5–1.1.7, draining approximately $600,000 from users of SushiSwap, Kyber, Revoke.cash, Zapper, and other protocols that integrated the library.

At current DeFi TVL levels, a TrapDoor-type compromise reaching deployer or bridge infrastructure at a mid-to-large protocol carries exposure in the $100 million to $300 million range, according to CryptoSlate's analysis.

Historical Precedent: Ledger, Axios, Lazarus

TrapDoor operates in a supply chain threat environment that has escalated materially in 2025–2026:

  • Ledger Connect Kit (December 2023): Former employee phished; malicious npm package drained ~$600,000 across multiple DeFi protocols within two hours.
  • Shai-Hulud (September 2025): ~600 npm package versions across ~200 unique names compromised over three days.
  • Shai-Hulud 2.0 (November 2025): 796 unique npm packages compromised, affecting over 20 million weekly downloads.
  • TeamPCP (February–March 2026): Trivy, KICS vulnerability scanners and LiteLLM (~3.4 million daily downloads) compromised. Malicious LiteLLM versions remained on PyPI for approximately three hours.
  • Axios (March 31, 2026): Approximately 100 million weekly downloads affected. CISA issued a formal supply chain compromise alert. The Lazarus Group was subsequently linked to the attack.

According to SecurityScorecard and Chainalysis, North Korea's Lazarus Group has stolen over $6 billion in cryptocurrency since 2017 and accounted for 76% of all DeFi hack losses in 2026 through direct exploits. Its parallel npm supply chain campaigns — including Operation Marstech Mayhem and the graphalgo series — constitute a separate but concurrent threat to the same developer population TrapDoor targets.

Malware on open-source registries increased 73% year-over-year in 2025, according to ReversingLabs' 2026 Software Supply Chain Security Report.

Detection and Response

Socket's automated detection infrastructure classified TrapDoor packages within minutes of publication:

| Metric | Value | |--------|-------| | Median detection time | 5 min 27 sec | | Fastest detection | 58 sec | | Average detection time | 5 min 56 sec | | Packages flagged | 34 | | Versions/artifacts flagged | 384+ |

The rapid detection prevented widespread adoption. However, the efficacy of automated registry scanning depends on threat intelligence coverage and heuristic sophistication. Packages that evade initial detection windows — even by hours, as in the TeamPCP/LiteLLM case — can propagate through dependency trees before removal.

CI/CD Mitigation Framework

Security Today's analysis, drawing on Socket's disclosure, outlines a 30-day hardening protocol for CI/CD environments:

Days 1–3: Enable egress filters on CI runners; restrict outbound network targets to explicit allowlists. This neutralizes exfiltration to novel domains.

Days 4–10: Deploy npm ci --ignore-scripts to prevent postinstall hook execution. Implement Software Bill of Materials (SBOM) generation for all dependency trees.

Days 11–20: Roll out OIDC federation for cloud credentials, deprecating long-lived tokens (AWS keys, GitHub PATs). This reduces the value of any single compromised secret.

Days 21–30: Version-control AI configuration files (.cursorrules, CLAUDE.md). Add Unicode-detection pre-commit hooks to flag zero-width character injection.

The regulatory context is tightening. NIS2 Article 21 requires documented supply chain risk assessments for entities in scope. DORA Articles 28–30 mandate ICT third-party inventory management for financial-sector participants, which increasingly includes DeFi teams operating within EU jurisdictions.

Key Takeaways

  • TrapDoor deployed 34 malicious packages across 384+ versions on npm, PyPI, and Crates.io between May 22–24, 2026, targeting crypto, DeFi, Solana, and AI developers.
  • The campaign is the first documented supply chain attack to weaponize AI coding assistant configuration files through zero-width Unicode injection.
  • Socket detected contaminated packages with a median time of 5 minutes 27 seconds, limiting adoption before flagging.
  • Direct financial losses are unquantified, but the attack model — compromising developer machines to reach deployer keys and bridge credentials — carries $100M–$300M exposure at mid-to-large DeFi protocols.
  • TrapDoor operates alongside Lazarus Group's separate npm campaigns (Axios, Marstech Mayhem), creating concurrent supply chain threats against the same developer population.
  • Registry-level malware increased 73% year-over-year in 2025, and three major multi-registry campaigns preceded TrapDoor in the prior eight months.

Conclusion

TrapDoor did not steal $100 million. By the metrics available, Socket's detection infrastructure prevented widespread package adoption. The campaign's significance is structural, not financial — it demonstrated a new class of supply chain vector targeting the AI-assisted development workflow that an increasing share of crypto protocol teams depend on.

The six-stage vulnerability chain from compromised developer workstation to mainnet deployment — developer machine, repository access, CI/CD pipelines, cloud accounts, deployment keys, production contracts — is not theoretical. Ledger's 2023 incident traversed it. The Axios compromise in March 2026 affected 100 million weekly downloads. TrapDoor added a seventh link: the AI coding assistant as an unwitting exfiltration agent.

For DeFi protocols managing material TVL, supply chain security is no longer a DevOps concern. It is a financial risk with quantifiable exposure, regulatory implications under NIS2 and DORA, and an adversary ecosystem that includes state-sponsored actors publishing malicious packages on the same registries protocol teams depend on daily.

Sources & References

  1. Socket Threat Research — TrapDoor Crypto Stealer Supply Chain Attack — Primary technical disclosure, May 24, 2026
  2. The Hacker News — TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware — Campaign coverage, May 25, 2026
  3. Cybersecurity News — Hackers Compromised 34 Packages in New Supply Chain Attack — Technical analysis, May 25, 2026
  4. Security Today — TrapDoor: Coordinated Supply-Chain Attack on npm, PyPI and Crates — CI/CD mitigation framework, May 25, 2026
  5. CryptoSlate — The Next Big DeFi Exploit Will Start Before the Code Is Deployed — Economic exposure analysis, May 26, 2026
  6. BanklessTimes — Crypto and AI Developers Hit by TrapDoor Malware Supply Chain Attack — Industry reporting, May 25, 2026
  7. CISA — Supply Chain Compromise Impacts Axios Node Package — Federal advisory on Axios npm compromise, April 20, 2026
  8. A Security Engineer — The Rise of Supply Chain Attacks: 2025–2026 — Historical supply chain attack data
  9. CoinDesk — Ledger Exploit Drained $484K, Upended DeFi — Ledger Connect Kit precedent, December 2023
  10. The Cyber Express — Lazarus Behind Axios npm Supply Chain Attack — Lazarus attribution for Axios, 2026