Acum 10 h
Socket Flags 'Trapdoor' Supply-Chain Malware in 34 Dev Packages Across 384 Versions
Socket investigators say a supply-chain campaign dubbed "Trapdoor" used malicious packages on npm, PyPI, and Crates.io to target crypto developers, aiming to steal wallet keys and other secrets. The firm reported the activity began with waves of package releases on May 22 and continued with updates over the following weekend, affecting 34 packages across 384 versions, some of which remained available.