{"schemaVersion":"guard-threat-campaign/v1","id":"HGTC-2026-TRAPDOOR26","slug":"trapdoor-cross-ecosystem-crypto-stealer","title":"TrapDoor cross-ecosystem crypto stealer","aliases":["TrapDoor"],"summary":"Socket documented a coordinated malicious-package campaign across npm, PyPI, and Crates.io that targeted developer credentials and wallets and included persistence through developer-tool instruction files.","status":"published","severity":"high","confidence":"high","uncertainty":"Package counts and removals changed during the investigation. This record describes the reviewed May 24 source and does not claim a complete or current inventory of every artifact.","firstObservedAt":"2026-05-22T20:20:18.000Z","lastObservedAt":"2026-05-24T00:00:00.000Z","publishedAt":"2026-08-09T11:30:00.000Z","reviewedAt":"2026-08-09T11:20:00.000Z","expiresAt":"2026-09-08T23:59:59.000Z","reviewer":"HOL Guard Research","sources":[{"id":"source:socket-trapdoor","label":"Socket: TrapDoor crypto stealer campaign","url":"https://socket.dev/blog/trapdoor-crypto-stealer-npm-pypi-crates","sourceType":"other_primary","observedAt":"2026-08-09T11:20:00.000Z"}],"artifacts":[{"id":"artifact:trapdoor-packages","artifactClass":"package","ecosystem":"npm/PyPI/Crates.io","name":"TrapDoor reviewed package set","version":null,"defanged":true}],"indicators":[],"timeline":[{"id":"timeline:first-observed","occurredAt":"2026-05-22T20:20:18.000Z","eventType":"first_observed","summary":"TrapDoor cross-ecosystem crypto stealer was first observed in the reviewed source material.","sourceIds":["source:socket-trapdoor"]},{"id":"timeline:disclosure","occurredAt":"2026-05-24T00:00:00.000Z","eventType":"disclosure","summary":"The reviewed source published or updated its defensive analysis and remediation guidance.","sourceIds":["source:socket-trapdoor"]}],"coverage":[{"assertionId":"coverage:stable:codex","relationship":"partial","limitation":"Guard can apply policy on eligible package-manager and Codex action surfaces, but the current manifest does not claim universal coverage for PyPI, Crates.io, persistence mechanisms, or already-executed malware."}],"policies":[{"policyId":"policy:package-install-review","purpose":"Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.","status":"available","limitation":"Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted."},{"policyId":"policy:agent-config-integrity-review","purpose":"Review unexpected changes to agent and editor instruction/configuration files before relying on the affected workspace.","status":"available","limitation":"Current Guard coverage is harness- and event-specific. Configuration changes made outside an observed surface may require separate repository or endpoint controls."}],"limitations":["Guard is complementary to dependency scanners, credential rotation, host incident response, and registry remediation after compromise."],"correctionHref":"/guard/security/campaigns/trapdoor-cross-ecosystem-crypto-stealer/corrections"}