On May 22, 2026, at 20:20 UTC, a coordinated supply chain attack designated TrapDoor began publishing malicious packages across three software registries: npm, PyPI, and Crates.io. Over the following 48 hours, the campaign deployed 34 malicious packages across 384+ versions, targeting developers ...
"TrapDoor targets teams building in crypto, DeFi, AI, and security, where a single hacked machine can leak high-value secrets." — Socket Threat Research Team
On May 22, 2026, at 20:20 UTC, a coordinated supply chain attack designated TrapDoor began publishing malicious packages across three software registries: npm, PyPI, and Crates.io. Over the following 48 hours, the campaign deployed 34 malicious packages across 384+ versions, targeting developers working in cryptocurrency, DeFi, Solana, and AI. The packages masqueraded as legitimate developer utilities — security scanners, deployment guards, prompt-engineering toolkits — while harvesting SSH keys, crypto wallet keystores, AWS credentials, GitHub tokens, browser data, and environment variables.
Socket, the supply chain security firm that disclosed the campaign on May 24, detected contaminated releases with a median response time of 5 minutes 27 seconds and a fastest detection of 58 seconds. No widespread adoption occurred before classification. However, TrapDoor's most significant feature was not the credential theft itself — it was the first documented supply chain attack to deliberately target AI coding assistants through zero-width Unicode injection in project configuration files, a vector that turns developer tooling into an exfiltration mechanism.
The attack arrives in a year when DeFi protocols have already lost $840 million to exploits, and supply chain compromises — including the Axios npm incident in March 2026 that affected approximately 100 million weekly downloads — are accelerating across the software ecosystem.
TrapDoor's operational structure spanned three package registries simultaneously — a first for crypto-targeted supply chain campaigns. The earliest artifact was eth-security-auditor@0.1.0 on PyPI, uploaded May 22, 2026 at 20:20:18 UTC. Subsequent packages were published in distinct waves from a cluster of accounts, including npm account asdxzxc and GitHub account ddjidd564.
The campaign's internal marker, P-2024-001, suggests planning predated execution by as much as two years.
Package names were engineered for credibility within crypto developer communities:
defi-threat-scanner, wallet-security-checker, crypto-credential-scannersolidity-deploy-guard, deployment-key-auditor, eth-wallet-sentinelprompt-engineering-toolkit, llm-context-compressor, model-switch-routersui-framework-helpers, move-compiler-tools, sui-sdk-build-utilsThe shared payload — a 48,485-byte JavaScript file called trap-core.js containing 1,149 lines — was consistent across ecosystems, deployed through registry-specific execution mechanisms.
npm (21 packages): Malicious code executed via postinstall hooks, triggering trap-core.js. Target assets included wallet keystores for Sui, Solana, and Aptos; SSH keys; AWS credentials; GitHub tokens; browser login databases; and environment variables. Persistence mechanisms included .cursorrules injection, Git hooks, shell hooks, systemd services, cron jobs, and SSH-based lateral movement.
PyPI (7 packages): Packages executed malicious code at import time, delegating to remote JavaScript hosted on an attacker-controlled GitHub Pages domain (ddjidd564.github.io/defi-security-best-practices/). The Python layer served primarily as a loader for the same trap-core.js payload, executed via node.
Crates.io (6 packages): All six targeted Sui and Move developers specifically. Malicious build.rs scripts executed during Rust compilation, using XOR encryption with the hardcoded key cargo-build-helper-2026 to obfuscate payloads. Exfiltration occurred through GitHub Gists.
TrapDoor introduced what security researchers describe as a control-plane attack on AI-assisted development. The campaign injected zero-width Unicode characters into .cursorrules and CLAUDE.md project configuration files — files read by AI coding assistants such as Cursor and Claude Code to establish project-level context and behavior rules.
These characters are invisible to human reviewers in standard code editors but are interpreted by AI language models as natural language prompts. The injected instructions directed AI assistants to execute what appeared to be automated security scans or diagnostics — routines that in practice collected and exfiltrated sensitive local data from the project context.
The attacker's GitHub account ddjidd564 also submitted pull requests to prominent open-source AI projects — including browser-use, LangChain, LangFlow, llama_index, MetaGPT, and OpenHands — proposing files described as "dev standards and build verification" that contained the same poisoned configurations.
This vector is structurally new. Previous supply chain attacks targeted build systems, package managers, or runtime dependencies. TrapDoor is the first documented campaign to weaponize the configuration layer between AI assistants and codebases, exploiting the trust relationship between developers and their AI tools.
The exfiltration infrastructure centered on GitHub Pages (ddjidd564.github.io) rather than dedicated command-and-control servers — a choice that complicates network-level detection, since GitHub domains typically pass corporate firewall allowlists.
The campaign marker P-2024-001 embedded in the payload suggests organizational structure and planning timelines extending well before the May 2026 deployment. No formal attribution has been published. TrapDoor has not been linked to the Lazarus Group, which operates its own distinct npm supply chain campaigns (including the Axios compromise of March 2026 and the earlier Operation Marstech Mayhem).
According to Socket, the campaign is not connected to the concurrent TrapDoor Android ad fraud operation that shares the name.
The direct financial losses from TrapDoor remain unquantified. Socket's rapid detection — median 5 minutes 27 seconds — limited package adoption before flagging. However, the attack model exposes a structural vulnerability in DeFi's value chain.
DeFi protocols are deployed by development teams whose local machines hold deployer private keys, multisig signer credentials, admin access tokens, and CI/CD pipeline secrets. A successful compromise of a single developer workstation can yield access to:
The Ledger Connect Kit hack of December 2023 demonstrated this chain in production: a phishing attack against a former employee's npm account led to malicious code in @ledgerhq/connect-kit versions 1.1.5–1.1.7, draining approximately $600,000 from users of SushiSwap, Kyber, Revoke.cash, Zapper, and other protocols that integrated the library.
At current DeFi TVL levels, a TrapDoor-type compromise reaching deployer or bridge infrastructure at a mid-to-large protocol carries exposure in the $100 million to $300 million range, according to CryptoSlate's analysis.
TrapDoor operates in a supply chain threat environment that has escalated materially in 2025–2026:
According to SecurityScorecard and Chainalysis, North Korea's Lazarus Group has stolen over $6 billion in cryptocurrency since 2017 and accounted for 76% of all DeFi hack losses in 2026 through direct exploits. Its parallel npm supply chain campaigns — including Operation Marstech Mayhem and the graphalgo series — constitute a separate but concurrent threat to the same developer population TrapDoor targets.
Malware on open-source registries increased 73% year-over-year in 2025, according to ReversingLabs' 2026 Software Supply Chain Security Report.
Socket's automated detection infrastructure classified TrapDoor packages within minutes of publication:
| Metric | Value | |--------|-------| | Median detection time | 5 min 27 sec | | Fastest detection | 58 sec | | Average detection time | 5 min 56 sec | | Packages flagged | 34 | | Versions/artifacts flagged | 384+ |
The rapid detection prevented widespread adoption. However, the efficacy of automated registry scanning depends on threat intelligence coverage and heuristic sophistication. Packages that evade initial detection windows — even by hours, as in the TeamPCP/LiteLLM case — can propagate through dependency trees before removal.
Security Today's analysis, drawing on Socket's disclosure, outlines a 30-day hardening protocol for CI/CD environments:
Days 1–3: Enable egress filters on CI runners; restrict outbound network targets to explicit allowlists. This neutralizes exfiltration to novel domains.
Days 4–10: Deploy npm ci --ignore-scripts to prevent postinstall hook execution. Implement Software Bill of Materials (SBOM) generation for all dependency trees.
Days 11–20: Roll out OIDC federation for cloud credentials, deprecating long-lived tokens (AWS keys, GitHub PATs). This reduces the value of any single compromised secret.
Days 21–30: Version-control AI configuration files (.cursorrules, CLAUDE.md). Add Unicode-detection pre-commit hooks to flag zero-width character injection.
The regulatory context is tightening. NIS2 Article 21 requires documented supply chain risk assessments for entities in scope. DORA Articles 28–30 mandate ICT third-party inventory management for financial-sector participants, which increasingly includes DeFi teams operating within EU jurisdictions.
TrapDoor did not steal $100 million. By the metrics available, Socket's detection infrastructure prevented widespread package adoption. The campaign's significance is structural, not financial — it demonstrated a new class of supply chain vector targeting the AI-assisted development workflow that an increasing share of crypto protocol teams depend on.
The six-stage vulnerability chain from compromised developer workstation to mainnet deployment — developer machine, repository access, CI/CD pipelines, cloud accounts, deployment keys, production contracts — is not theoretical. Ledger's 2023 incident traversed it. The Axios compromise in March 2026 affected 100 million weekly downloads. TrapDoor added a seventh link: the AI coding assistant as an unwitting exfiltration agent.
For DeFi protocols managing material TVL, supply chain security is no longer a DevOps concern. It is a financial risk with quantifiable exposure, regulatory implications under NIS2 and DORA, and an adversary ecosystem that includes state-sponsored actors publishing malicious packages on the same registries protocol teams depend on daily.