Reviewed threat campaign

TrapDoor cross-ecosystem crypto stealer

Socket documented a coordinated malicious-package campaign across npm, PyPI, and Crates.io that targeted developer credentials and wallets and included persistence through developer-tool instruction files.

Severity highConfidence highReviewed 2026-08-09Expires 2026-09-08

Uncertainty

Package counts and removals changed during the investigation. This record describes the reviewed May 24 source and does not claim a complete or current inventory of every artifact.

Limitations

Timeline

  1. · TrapDoor cross-ecosystem crypto stealer was first observed in the reviewed source material.
  2. · The reviewed source published or updated its defensive analysis and remediation guidance.

Publication clock: 1859.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.

Guard coverage and non-coverage

Defensive policy guidance

Sources