← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] TrapDoor Malware Hits 34 Packages, Poisons AI Assistants

Zephyra|May 29, 2026|BPF
EXECUTIVE SUMMARY

A coordinated supply chain attack designated TrapDoor planted 34 malicious packages across 384 versions on npm, PyPI, and Crates.io beginning May 22, 2026. The campaign targets developers building on Solana, Sui, and Aptos, stealing wallet keystores, SSH keys, AWS credentials, GitHub tokens, and ...

"The goal appears to be to trick AI assistants into running a 'security scan' or similar workflow that causes secret discovery and exfiltration." — Ahmad Nassri, CTO, Socket

Executive Summary

A coordinated supply chain attack designated TrapDoor planted 34 malicious packages across 384 versions on npm, PyPI, and Crates.io beginning May 22, 2026. The campaign targets developers building on Solana, Sui, and Aptos, stealing wallet keystores, SSH keys, AWS credentials, GitHub tokens, and browser data. Security firm Socket, which identified the operation, flagged packages in a median time of 5 minutes 27 seconds after publication. No confirmed victims or stolen funds have been reported.

TrapDoor introduces a technique not previously observed at scale in supply chain attacks: poisoning AI coding assistant configuration files — specifically .cursorrules and CLAUDE.md — with zero-width Unicode characters that hide malicious prompts from human review but remain parseable by AI tools. The attackers also opened pull requests against six major open-source AI repositories including LangChain, LlamaIndex, and MetaGPT, attempting to propagate the poisoned configuration files into projects with millions of downstream users. None of those PRs were merged.

The campaign lands amid a 75% year-over-year increase in open-source malware, with Sonatype's 2026 State of the Software Supply Chain report documenting over 454,600 new malicious packages in 2025 alone. npm accounts for over 99% of detected open-source malware.

Table of Contents

  1. Campaign Timeline and Scope
  2. Package Anatomy: Three Ecosystems, One Payload
  3. AI Assistant Poisoning: The New Attack Vector
  4. Exfiltration Infrastructure
  5. Detection and Response
  6. Context: The Escalating Supply Chain Threat to Crypto
  7. Implications for Web3 Developer Security
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

Campaign Timeline and Scope

The earliest TrapDoor artifact Socket identified was the PyPI package eth-security-auditor@0.1.0, uploaded on May 22, 2026 at 20:20:18 UTC. Additional packages were published in waves from a cluster of accounts through the weekend.

The campaign distributed packages across three registries:

| Registry | Packages | Examples | |----------|----------|----------| | npm | 21 | crypto-credential-scanner, defi-threat-scanner, wallet-security-checker, web3-secrets-detector, llm-context-compressor | | PyPI | 7 | eth-security-auditor, cryptowallet-safety, defi-risk-scanner, solidity-build-guard | | Crates.io | 6 | move-analyzer-build, sui-framework-helpers, sui-sdk-build-utils, sui-move-build-helper |

Package names were deliberately designed to appear as legitimate developer utilities — security scanners, build helpers, and configuration tools. The Crates.io packages specifically targeted the Move programming language ecosystem used by Sui and Aptos, while PyPI and npm packages targeted Solana and Ethereum developer workflows.

Socket documented 384 total versions and artifacts across these 34 packages, indicating rapid iteration. According to Socket, the GitHub activity associated with the campaign "shows signs of rapid, AI-assisted-style iteration: broad security-themed scaffolding, generic lure repositories, prompt-injection documentation, and partially implemented extraction concepts mixed with working malware components."

Package Anatomy: Three Ecosystems, One Payload

Each ecosystem used a different activation mechanism tailored to its package manager's lifecycle:

npm: 21 packages used postinstall hooks to deploy a shared payload file called trap-core.js, a 48,485-byte file containing 1,149 lines. This payload uses Fernet and ECDH encryption and validates stolen AWS and GitHub credentials through live API calls to identify high-value targets before full exfiltration.

PyPI: 7 packages executed remote JavaScript on import via node -e, downloading payloads from attacker-controlled GitHub Pages domains. This approach allows post-publication payload updates without releasing new package versions — the malware's behavior can change after installation.

Crates.io: 6 packages used malicious build.rs scripts that execute during Rust's standard compilation process. These used XOR-based encryption with the hardcoded key cargo-build-helper-2026 and exfiltrated data to GitHub Gists.

All three vectors fire automatically during standard install and compile operations: npm install, pip install, and cargo build. No user interaction beyond the initial dependency resolution is required.

The exfiltration target list is extensive:

  • Sui, Solana, and Aptos wallet keystores
  • SSH private keys
  • AWS credentials and environment variables
  • GitHub Personal Access Tokens
  • Browser profile data and login databases
  • Crypto wallet browser extension data
  • API keys and local development configuration files

Each exfiltration payload includes a complete environment fingerprint: hostname, platform, architecture, Node.js version, username, current working directory, and up to 500 credential match results. The campaign uses the marker P-2024-001 across related components.

AI Assistant Poisoning: The New Attack Vector

TrapDoor's defining characteristic is its deliberate targeting of AI coding assistants. The npm payload plants .cursorrules and CLAUDE.md files in project directories. These files embed hidden instructions using four types of zero-width Unicode characters:

  • U+200B (zero-width space)
  • U+200C (zero-width non-joiner)
  • U+200D (zero-width joiner)
  • U+FEFF (byte order mark)

These characters render the malicious instructions invisible in standard code editors and file browsers while remaining fully accessible to AI text parsers. Tools such as Cursor and Claude Code parse the full Unicode stream and act on the embedded directives, triggering a fake "security scan" that silently discovers and exfiltrates local secrets.

The technique extends beyond the malicious packages themselves. Socket identified pull requests opened against six major open-source AI repositories:

  1. browser-use/browser-use
  2. langchain-ai/langchain
  3. langflow-ai/langflow
  4. run-llama/llama_index
  5. FoundationAgents/MetaGPT
  6. OpenHands/OpenHands

Each PR was titled "docs: add .cursorrules with dev standards and build verification" and pointed to ddjidd564.github.io/defi-security-best-practices/config.json while embedding the same P-2024-001 campaign marker. None were merged before detection.

The implication is significant: if any of those PRs had been merged, every developer cloning LangChain, LlamaIndex, or MetaGPT who uses an AI coding assistant would have had their local environment silently scanned without installing any malicious package. This represents a supply chain attack that bypasses package managers entirely, operating through repository-level configuration files.

Socket stated this is the first confirmed campaign to deliver this AI poisoning technique via supply chain at mass scale and to attempt propagation into major open-source repositories through fraudulent pull requests.

Exfiltration Infrastructure

The threat actors used GitHub infrastructure for command-and-control:

  • GitHub account: ddjidd564
  • Payload delivery: GitHub Pages at ddjidd564[.]github[.]io/defi-security-best-practices/
  • Configuration endpoint: config.json served from the same domain
  • Data exfiltration: GitHub Gists (Crates.io packages) and webhook.site (fallback)

The defi-security-best-practices repository contained documentation files including AUDIT-MATRIX.md, BYPASS.md, PAYLOAD.md, and SWARM.md — files describing extraction frameworks and persistence strategies. The use of legitimate GitHub infrastructure for command-and-control complicates network-level detection, as traffic to github.io domains does not typically trigger security alerts.

Persistence mechanisms included cron jobs, systemd services, Git hooks, shell hooks, and SSH-based lateral movement capabilities. The malware attempts SSH-based propagation to other systems accessible from the compromised developer environment.

Detection and Response

Socket's detection performance across 381 package-version records with complete timestamps:

| Metric | Time | |--------|------| | Average detection time | 5 minutes 56 seconds | | Median detection time | 5 minutes 27 seconds | | Fastest single detection | 58 seconds |

Socket classified all 34 packages as malicious and reported them to the affected registries. The packages have since been removed from npm, PyPI, and Crates.io. SlowMist, a blockchain security firm, issued an independent warning confirming the threat.

Socket did not identify confirmed victims or quantify stolen funds. The absence of confirmed victims does not establish the campaign's failure — credential theft payloads may have executed within the detection window, and exfiltrated credentials could be exploited on a delayed timeline.

Context: The Escalating Supply Chain Threat to Crypto

TrapDoor does not exist in isolation. The 2026 software supply chain threat landscape targeting crypto developers has escalated substantially:

Sonatype 2026 Report: Open-source malware surpassed 1.233 million cumulative packages, with 454,600 new malicious packages identified in 2025 — a 75% year-over-year increase. Over 99% occurred on npm. Annual open-source downloads reached 9.8 trillion, up 67% year-over-year.

Axios npm Compromise (March 31, 2026): North Korea's Lazarus Group (BlueNoroff subgroup) socially engineered the lead maintainer of the Axios npm package — downloaded approximately 100 million times per week and present in roughly 80% of cloud environments — to publish malicious versions. Microsoft Threat Intelligence and Google Threat Intelligence Group attributed the attack to UNC1069, a North Korean state actor. Observed execution occurred in 3% of affected environments.

Shai-Hulud Worm (September 2025): The first known self-replicating npm malware, capable of propagating autonomously through developer environments. The "Mini Shai-Hulud" successor in May 2026 compromised the TanStack GitHub Actions CI pipeline, publishing 84 malicious artifacts across 42 @tanstack/* packages within six minutes.

North Korea's Cumulative Impact: According to multiple threat intelligence sources, the Lazarus Group has stolen over $6 billion in cryptocurrency since 2017 and accounts for 76% of all hack-related crypto losses in 2026. Sonatype identified more than 800 Lazarus-associated packages, 97% concentrated in npm.

Implications for Web3 Developer Security

TrapDoor exposes three structural vulnerabilities in the Web3 development stack:

1. Package registry trust models are inadequate. npm, PyPI, and Crates.io allow anonymous publication with minimal vetting. The 5-minute-56-second average detection window means any CI/CD pipeline that runs during that interval is exposed. Current registry trust models assume packages are safe until proven otherwise — the inverse of the security posture that crypto asset custody demands.

2. AI coding assistants create a new attack surface. The zero-width Unicode technique turns AI assistants into unwitting agents for credential exfiltration. As AI-assisted development becomes standard practice in Web3 — particularly for smart contract development and protocol engineering — this vector will expand. Configuration files like .cursorrules and CLAUDE.md are not subject to the same scrutiny as source code, and AI tools parse them with full trust.

3. The economic value at risk is asymmetric. A developer working on a DeFi protocol with $100 million in TVL has access to deployment keys, multisig configurations, and infrastructure credentials. A single compromised developer environment could enable losses orders of magnitude larger than the cost of the attack. The value distribution framework applies here: the economic value created by developer tooling infrastructure flows to whichever party controls access — in this case, the attacker.

The broader pattern is clear. Supply chain attacks against crypto developers are shifting from crude typosquatting to multi-ecosystem, multi-vector campaigns that combine package poisoning, AI manipulation, and social engineering. The attacker's cost is minimal — registering accounts and publishing packages is free — while the potential payoff from compromising a single high-value developer environment is substantial.

Key Takeaways

  • TrapDoor planted 34 malicious packages across 384 versions on npm, PyPI, and Crates.io between May 22-25, 2026, targeting Solana, Sui, and Aptos wallet keystores, SSH keys, and cloud credentials.
  • The campaign introduced AI assistant poisoning at scale, using zero-width Unicode characters in .cursorrules and CLAUDE.md files to trick AI coding tools into executing credential exfiltration.
  • Pull requests were opened against LangChain, LlamaIndex, MetaGPT, and three other major AI repositories; none were merged.
  • Socket detected malicious packages in a median of 5 minutes 27 seconds; no confirmed victims or stolen funds have been reported.
  • The campaign uses GitHub infrastructure (Pages, Gists) for command-and-control, complicating network-level detection.
  • Open-source malware grew 75% year-over-year to 454,600 new malicious packages in 2025, per Sonatype. npm accounts for over 99% of detected malware.
  • Web3 developers face escalating supply chain risk from state-linked actors (Lazarus Group, responsible for 76% of 2026 crypto hack losses) and independent campaigns like TrapDoor.

Conclusion

TrapDoor represents an operational evolution in supply chain attacks against the crypto development ecosystem. The combination of cross-registry package distribution, AI assistant manipulation, and repository-level PR poisoning constitutes a multi-vector approach that targets the full development workflow — from dependency installation to code generation. The campaign's use of zero-width Unicode characters to subvert AI coding tools is a technique that will likely be replicated and refined by other threat actors.

The economic calculus is straightforward: the cost of publishing malicious packages across three registries is near zero, while the potential value of credentials extracted from a single DeFi protocol developer is measured in millions. Socket's sub-six-minute detection time narrows but does not close this window. Until package registries adopt pre-publication vetting, and AI coding tools implement Unicode normalization and configuration file sandboxing, the attack surface will remain open.

For Web3 development teams, the immediate mitigations are practical: audit .cursorrules and CLAUDE.md files for hidden Unicode characters, pin dependencies to verified hashes, run installations in sandboxed environments, and treat AI-generated security scan suggestions with the same skepticism as unsolicited email attachments.

Sources & References

  1. TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages — Socket Research Team primary analysis, May 2026
  2. TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO — The Hacker News coverage, May 2026
  3. Solana, Sui and Aptos wallet data targeted in TrapDoor package attack — CoinDesk, May 29, 2026
  4. TrapDoor Malware Targets Crypto Developer Tools — Cointelegraph, May 2026
  5. TrapDoor Malware Campaign Targets Crypto Developer Environments With 34+ Malicious Packages — Unchained Crypto, May 2026
  6. TrapDoor Supply Chain Campaign: Cross-Ecosystem Credential Theft and AI Assistant Poisoning — Phoenix Security analysis, May 2026
  7. TrapDoor: Supply Chain Attack Poisons AI Coding Assistants — Cloud Security Alliance Lab Space, May 2026
  8. Sonatype 2026 State of the Software Supply Chain Report — Open source malware statistics
  9. North Korea's $6 Billion Crypto Crime Spree: The Full Picture in 2026 — Crypto Impact Hub, 2026
  10. SlowMist Threat Intelligence: TrapDoor Analysis — SlowMist, May 2026