TrapDoor cross-ecosystem crypto stealer
Socket documented a coordinated malicious-package campaign across npm, PyPI, and Crates.io that targeted developer credentials and wallets and included persistence through developer-tool instruction files.
Also tracked as TrapDoor
- First observed
- May 22, 2026
- Last observed
- May 24, 2026
- Last reviewed
- Sep 2, 2026
- Tracking ended
- Sep 8, 2026
Record exports
Uncertainty and limitations
Read the evidence limits before acting on this record.
Package counts and removals changed during the investigation. This record describes the reviewed May 24 source and does not claim a complete or current inventory of every artifact.
- Guard is complementary to dependency scanners, credential rotation, host incident response, and registry remediation after compromise.
Guard coverage and policy
What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.
Not covered, or partially covered
partial
Guard can apply policy on eligible package-manager and Codex action surfaces, but the current manifest does not claim universal coverage for PyPI, Crates.io, persistence mechanisms, or already-executed malware.
- Recipe available
Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.
Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.
- Recipe available
Review unexpected changes to agent and editor instruction/configuration files before relying on the affected workspace.
Current Guard coverage is harness- and event-specific. Configuration changes made outside an observed surface may require separate repository or endpoint controls.
Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.
Timeline
Reviewed events, oldest first, each tied to a verified source.
- First observed
TrapDoor cross-ecosystem crypto stealer was first observed in the reviewed source material.
- Disclosure
The reviewed source published or updated its defensive analysis and remediation guidance.
Publication clock: 1859.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Reviewed artifacts
The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.
TrapDoor reviewed package setnpm/PyPI/Crates.iopackage
Sources
Every claim on this record is traceable to the sources below.
Record HGTC-2026-TRAPDOOR26