TrapDoor malware campaign steals crypto wallet data through fake… — Crypto LVL — TG.ME

🔔 TrapDoor malware campaign steals crypto wallet data through fake developer tools

📈 TrapDoor malware has emerged as a new threat to crypto and AI developers after researchers uncovered a supply chain attack designed to steal wallet data, API keys, cloud credentials, and SSH access through poisoned developer packages.

➡️ According to a report published Sunday by developer security platform Socket, the campaign, dubbed “TrapDoor,” was first identified on Friday and has already spread through at least 34 malicious packages and 384 connected versions across multiple software ecosystems. Socket said the attackers have focused on developers working in cryptocurrency, decentralized finance, artificial intelligence, and security infrastructure, where exposed credentials can provide access to wallets, repositories, cloud environments, and internal systems.

📊 vAmong the targeted services are wallets and platforms linked to Coinbase, Binance, MetaMask, Brave, along with blockchain ecosystems tied to Solana, Sui, and Aptos. Ahmad Nassri, chief technology officer at Socket, said the malware also attempts to manipulate AI coding assistants such as Claude and Cursor by injecting hidden prompts into development workflows. Socket’s report stated that the attackers appear to be pushing AI tools into running fake “security scans” that expose secrets and transmit them back to the operators.
May 25, 2026 18.5K 89