A recent report by Socket Security has revealed an ongoing supply chain attack named TrapDoor, targeting software package repositories such as npm, PyPI, and Crates.io. According to ChainCatcher, the attack has already resulted in the discovery of 34 malicious software packages and 384 versions and artifacts, with attackers continuously releasing new versions across these ecosystems.
TrapDoor specifically targets developers in the cryptocurrency, DeFi, AI, and security sectors. The attack aims to steal sensitive information, including wallet data, SSH keys, cloud credentials, GitHub tokens, browser data, environment variables, and API keys. Socket Security noted that the median detection time for these malicious versions is 5 minutes and 27 seconds, with the fastest detection occurring just 58 seconds after release.