A Massive Malware Campaign Is Now Targeting Crypto And AI Developers
-

Cybersecurity platform Socket has uncovered an active supply chain attack called TrapDoor that specifically targets crypto, AI, and Web3 developers through malicious software packages hidden inside popular developer ecosystems. Researchers identified more than 34 malicious packages and hundreds of infected versions designed to steal wallet data, cloud credentials, API keys, SSH keys, GitHub tokens, and browser extension information.What makes this campaign especially dangerous is its scale and targeting strategy. The malware was discovered across major developer repositories including npm for JavaScript, PyPI for Python, and Crates for Rust, giving attackers access to some of the most widely used software ecosystems in crypto and AI development today.
-
ai generated code and automated dependency management may unintentionally increase exposure if developers blindly trust external suggestions and libraries