Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    CLARITY Act Shields Crypto Developers, But One Criminal Line Could Gut It
    CLARITY Act Shields Crypto Developers, But One Criminal Line Could Gut It
    The Web3 Job Scam Draining Crypto Wallets Worldwide
    The Web3 Job Scam Draining Crypto Wallets Worldwide
    BlackRock Tokenized Treasury Filings 2026 The RWA Boom Goes Institutional
    BlackRock Tokenized Treasury Filings 2026: The RWA Boom Goes Institutional
    Bitcoin Pizza Day: How 10,000 BTC Turned into real money
    Bitcoin Pizza Day: How 10,000 BTC Turned Monopoly Money Into Real Money
    CLARITY Act Clears Senate Banking Committee 15-9 Here’s What Every Crypto Leader Is Saying
    CLARITY Act Clears Senate Banking Committee 15-9: Here’s What Every Crypto Leader Is Saying
  • Opinion
    OpinionShow More
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
    Bitcoin Pizza Day Was Never Really About Pizza
    Bitcoin Pizza Day Was Never Really About Pizza
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
    WazirX Debuts ‘Guardians of Trust’ Hub Security Pivot or Distraction from the 15% Debt
    WazirX Debuts ‘Guardians of Trust’ Hub: Security Pivot or Distraction from the 15% Debt?
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

SlowMist Says TrapDoor is One of 2026’s Largest Supply Chain Attacks

The report said that researchers found 34 malicious packages and 384 infected versions targeting crypto, DeFi, Solana, Sui, and AI developers.

Written By:
Kenrodgers Fabian

Reviewed By:
Dishita Malvania

Last updated: 1 hour ago
Published 1 hour ago
Share
Last updated: 1 hour ago
Published 1 hour ago
SlowMist Says TrapDoor is One of 2026’s Largest Supply Chain Attacks
Show AI Summary
Attackers inserted malicious code into installation and build processes, activating malware automatically upon dependency downloads
Over 34 malicious packages and 384 infected versions were uploaded to npm, PyPI, and Crates.io, targeting crypto and AI developers
Malware stole sensitive data, including SSH keys and AWS credentials, by disguising traffic as normal coding activity via trusted services

Cybersecurity researchers have uncovered a major software supply chain attack that targeted crypto and artificial intelligence (AI) developers across several popular open-source platforms. Security firm SlowMist said the campaign, known as “TrapDoor,” spread through malicious software packages uploaded to npm, PyPI, and Crates.io, exposing crypto wallets, cloud credentials, and sensitive developer access keys.

The warning came after security platform Socket first identified the operation on May 24. Researchers said attackers uploaded more than 34 malicious packages and 384 infected versions disguised as legitimate developer tools. The campaign mainly targeted teams building crypto, DeFi, Solana, Sui, and AI-related applications.

✍️We have released an in-depth technical analysis report on the #TrapDoor cross-ecosystem supply chain credential theft campaign.

TrapDoor was first disclosed by the @SocketSecurity on May 24. Subsequently, we conducted continuous threat hunting through our MistEye threat… https://t.co/dh3vGfuux2

— SlowMist (@SlowMist_Team) May 28, 2026

According to SlowMist, the attackers inserted hidden malicious code directly into the installation and build processes. Consequently, the malware activated automatically once developers downloaded dependencies or opened compromised projects inside coding environments. Researchers described the incident as one of the largest cross-platform supply chain attacks seen in 2026 because the same infrastructure operated across multiple programming ecosystems.

Attackers exploited trusted developer tools

SlowMist said the attackers used trusted developer services such as GitHub Pages, GitHub Gists, and webhook.site to disguise malicious traffic as normal coding activity. The malware reportedly stole SSH keys, browser session data, AWS credentials, crypto wallet files, and API tokens before sending the information to remote servers controlled by the attackers.

Researchers also found strong connections between the Python and npm versions of the malware through shared infrastructure linked to the domain ddjidd564.github.io. However, the Rust-based sample showed fewer similarities, even though it targeted many of the same crypto-focused developers.

According to SlowMist, the npm version appeared to be the most sophisticated part of the operation. Besides stealing credentials, the malware altered Git hooks, shell profiles, and files linked to AI coding assistants, including .cursorrules and CLAUDE.md. Researchers said the attackers also tried to spread malicious instructions through AI-assisted coding workflows using hidden zero-width characters and prompt injection methods.

AI coding assistants become a new security risk

Researchers warned that the campaign exposed growing risks for developers who increasingly depend on AI coding assistants in daily workflows. According to SlowMist, the malware carried hidden instructions designed to influence tools such as Cursor and Claude Code during future coding sessions, potentially allowing malicious behavior to spread beyond the initial infection.

The report said the attackers turned routine software package installations into long-term access points inside developer systems. Moreover, the malware quietly restored itself through shell scripts and Git-related operations without drawing attention from users.

SlowMist urged affected developers to rotate credentials immediately, remove compromised packages, and scan systems for indicators linked to the “P-2024-001” marker and associated domains. 

Also Read: HTX Says Frozen Funds Restored After “Technical Mishap” Sparks Chaos

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:BlockchainCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Dishita Malvania - Senior crypto journalist at The Crypto Times
By Dishita Malvania
Follow:
Dishita Malvania is a Crypto Journalist with 3 years of experience covering the evolving landscape of blockchain, Web3, AI, finance, and B2B tech. With a background in Computer Science and Digital Media, she blends technical knowledge with sharp editorial insight. Dishita reports on key developments in the crypto world—including Litecoin, WazirX, Solana, Cardano, and broader blockchain trends—alongside interviews with notable figures in the space. Her work has been referenced by top digital media outlets like Entrepreneur.com, The Independent, The Verge, and Metro.co, especially on trending topics like Elon Musk, memecoins, Trump, and notable rug pulls.

Latest News

Vitalik Buterin Reveals New Tools for Secure AI and Crypto Access
Vitalik Buterin Reveals New Tools for Secure AI and Crypto Access
Exchange-Owned Chains on OP Stack Generated Over $495M in App Revenue in H2 2025
Exchange-Owned Chains on OP Stack Generated Over $495M in App Revenue in H2 2025
Bit Digital Buys Ethereum worth $20M as Treasury Surpasses 158K ETH
Bit Digital Buys Ethereum worth $20M as Treasury Surpasses 158K ETH
Stake DAO Assures Users After vsdCRV Exploit and Bridge Shutdown
Stake DAO Assures Users After vsdCRV Exploit and Bridge Shutdown
Sequans Ditches Bitcoin Treasury: Sells BTC Holdings to Redeem Debt and Refocus on IoT Chips
Sequans Ditches Bitcoin Treasury: Sells BTC Holdings to Redeem Debt and Refocus on IoT Chips

Find Us on Socials

You may also like

BIS to Test Real Money Blockchain System to Speed Up Global Payments

BIS to Test Real Money Blockchain System to Speed Up Global Payments

DTCC Announces Plans to Tokenize Custodied Assets on Stellar Network

DTCC Announces Plans to Tokenize Custodied Assets on Stellar Network 

Stake DAO Exploited as Hacker Mints 5.4 Trillion Fake vsdCRV

Stake DAO Exploited as Hacker Mints 5.4 Trillion Fake vsdCRV

“All of DeFi Is Unsafe” OpenZeppelin Founder Sounds Alarm on AI Exploits

“All of DeFi Is Unsafe”: OpenZeppelin Founder Sounds Alarm on AI Exploits

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information