TrapDoor Malware Campaign Targets Developers Across npm, PyPI, and Crates.io
A new software supply chain attack known as TrapDoor is putting developers, crypto projects, and AI coding workflows on high alert. The campaign involved 34 malicious packages spread across three major open-source registries: npm, PyPI, and Crates.io.
Security researchers publicly identified the campaign on May 25, 2026, after tracing its earliest activity back to May 19. The largest wave arrived on May 22 at 20:20 UTC, suggesting a carefully timed operation designed to strike when fewer security teams were watching. By the time the campaign was exposed, attackers had already pushed 384 package versions across the affected registries.
TrapDoor was not a random malware dump. The package names were crafted to look useful, especially to developers working in crypto, blockchain, DeFi, Solana, wallet security, and AI tooling. Names such as eth-security-auditor, prompt-engineering-toolkit, defi-threat-scanner, wallet-security-checker, and solidity-deploy-guard were designed to blend into normal developer workflows.
Behind the harmless-looking names, however, the packages carried a highly aggressive payload.
TrapDoor was built to steal sensitive developer data, including crypto wallet files, SSH keys, cloud credentials, AWS tokens, GitHub tokens, browser data, environment variables, and other secrets stored on local machines. Once installed or executed, the malware attempted to collect credentials quickly and quietly, then send the stolen data to attacker-controlled infrastructure.
The attack methods varied depending on the software registry.
On npm, malicious packages used postinstall hooks to drop a file called trap-core.js. This script checked stolen tokens against live AWS and GitHub services to confirm whether they were valid. It also attempted to maintain access through cron jobs, systemd services, Git hooks, and SSH-related persistence methods.
On PyPI, the malicious packages triggered when imported. Instead of storing the full payload directly in the Python package, they fetched JavaScript from an external attacker-controlled domain. This gave the attackers flexibility: they could update the malicious code without needing to republish the PyPI package itself.
On Crates.io, the Rust packages used a build.rs script to run during the build process. These packages searched for local keystores and then pushed XOR-encrypted stolen data to GitHub Gists, making the exfiltration harder to spot at a glance.
One of the most worrying parts of TrapDoor is its focus on AI-assisted development. The campaign did not only target package managers. It also attempted to poison repositories used by AI coding tools.
The attackers planted files such as .cursorrules and CLAUDE.md into target projects. These files appeared ordinary during review, but they contained hidden instructions embedded with zero-width Unicode characters. A human reviewer might see nothing suspicious. An AI coding assistant, however, could interpret the hidden text as instructions.
The goal was simple and dangerous: make the AI assistant believe it was running a normal security scan while actually executing commands that steal secrets from the developer’s machine.
The attackers also opened pull requests against popular open-source AI and automation projects, including BrowserUse, LangChain, and LangFlow. This appears to have been a test to see whether the poisoned files could pass through a standard code review process. If merged into a trusted repository, the malicious instructions could reach every developer who opened the project with an AI coding assistant.
That makes TrapDoor especially significant. The threat is no longer limited to installing a bad package from a registry. The developer’s editor, AI assistant, and repository configuration files are now part of the attack surface.
TrapDoor shows how software supply chain attacks are evolving in 2026. Attackers are not just looking for vulnerable servers or exposed databases. They are targeting the tools developers trust every day: package managers, code editors, build scripts, Git workflows, and AI coding assistants.
Developers should treat unfamiliar packages with caution, even when they appear to match a legitimate use case. Teams should also audit dependency additions, review postinstall scripts, inspect build scripts, monitor outbound connections, and scan repositories for unusual configuration files or hidden Unicode characters.
AI coding tools can improve productivity, but they also introduce new security risks when they read and act on repository instructions automatically. Any file that influences an AI assistant’s behavior should be reviewed with the same care as executable code.
The TrapDoor campaign is a clear warning: modern malware does not always arrive as an obvious executable. Sometimes it looks like a helpful security scanner, a crypto utility, or a harmless AI configuration file. For developers, the safest assumption is that every new dependency and every automation instruction deserves scrutiny before it runs.






