Reviewed threat campaign
TrapDoor cross-ecosystem crypto stealer
Socket documented a coordinated malicious-package campaign across npm, PyPI, and Crates.io that targeted developer credentials and wallets and included persistence through developer-tool instruction files.
Uncertainty
Package counts and removals changed during the investigation. This record describes the reviewed May 24 source and does not claim a complete or current inventory of every artifact.
Limitations
- Guard is complementary to dependency scanners, credential rotation, host incident response, and registry remediation after compromise.
Timeline
- · TrapDoor cross-ecosystem crypto stealer was first observed in the reviewed source material.
- · The reviewed source published or updated its defensive analysis and remediation guidance.
Publication clock: 1859.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Guard coverage and non-coverage
- partial: coverage:stable:codex — Guard can apply policy on eligible package-manager and Codex action surfaces, but the current manifest does not claim universal coverage for PyPI, Crates.io, persistence mechanisms, or already-executed malware.
Defensive policy guidance
- Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.
Status: available. Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted. - Review unexpected changes to agent and editor instruction/configuration files before relying on the affected workspace.
Status: available. Current Guard coverage is harness- and event-specific. Configuration changes made outside an observed surface may require separate repository or endpoint controls.
Sources
- Socket: TrapDoor crypto stealer campaign · observed 2026-08-09