A new supply-chain threat is putting one of crypto’s most trusted habits under pressure: installing everyday coding tools. Researchers say the TrapDoor malware crypto developers need to watch for is spreading through fake packages that look routine, then quietly siphoning off wallet data, API keys, cloud credentials, and SSH access.
That matters because the targets are not random users clicking suspicious links. Instead, this campaign is aimed at developers working in cryptocurrency, DeFi, artificial intelligence, and security infrastructure, where a single exposed credential can open the door to wallets, repositories, cloud systems, and internal environments.
Socket, the developer security platform tracking the activity, said the operation has already moved through more than 34 malicious developer packages across npm, PyPI, and Rust ecosystems, affecting at least 384 connected versions. As a result, the scale points to a broad attempt to poison the software supply chain
We współpracy z: https://en.cryptonomist.ch/2026/05/25/trapdoor-malware-crypto-developers/