Socket’s May 24 disclosure of TrapDoor found more than 34 malicious packages and over 384 related versions spread across npm, PyPI, and Crates.io, each targeting the developers who build and maintain protocols, and the credentials that govern access to the systems around them.
What TrapDoor built is a route from a single developer’s compromised machine into the repositories, CI/CD pipelines, cloud accounts, and deployment keys that govern how protocols reach mainnet and stay updated once deployed.
Socket’s report confirms credential theft and infrastructure exposure as the campaign’s documented scope, leaving on-chain exploits as the inferred downstream consequence.
A six-stage flowchart shows how a malicious package moves from developer machine compromise through credential theft to put user funds at risk.
The attack surface developers don’t audit
The campaign delivered payloads through ordinary developer workflows, such as npm packages executing malicious code through postinstall hoo
We współpracy z: https://cryptoslate.com/the-next-big-defi-exploit-will-start-before-the-code-is-deployed/