Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesStocksEarnInstitutionAI & More
Researchers flag TrapDoor malware campaign targeting crypto developer environments including Aptos, Sui and Solana

Researchers flag TrapDoor malware campaign targeting crypto developer environments including Aptos, Sui and Solana

The BlockThe Block2026/05/25 09:54
By:The Block

Researchers at Socket Security identified more than 34 malicious packages across three programming language registries targeting crypto developer environments, including Aptos, Sui, and Solana ecosystems.

Dubbed TrapDoor, the campaign spans npm, PyPI, and Crates.io with over 384 total versions. Malicious packages identified include sui-framework-helpers, sui-move-build-helper, and move-analyzer-build on Crates.io, alongside multiple npm and PyPI packages, Socket researchers said in a statement on Sunday. 

The researchers said the malware is designed to steal SSH keys, wallet keystores, AWS credentials, GitHub tokens, and browser login databases from developer machines. The packages execute through ecosystem-specific mechanisms, including npm postinstall hooks, Python import triggers, and Rust build.rs scripts.

According to Socket Security, the earliest package observed was the PyPI module [email protected], uploaded on Friday at 20:20 UTC, with a compiled wheel published two minutes later. The packages were released in rapid succession by multiple accounts and appeared across registries in tightly clustered deployment waves, per the report.

The npm packages in the campaign included tools such as crypto-credential-scanner, defi-env-auditor, and wallet-security-checker, while Crates.io packages focused on Sui and Move development tooling, including move-project-builder and sui-sdk-build-utils. PyPI packages included eth-security-auditor and defi-risk-scanner, designed to execute automatically during standard development workflows.

Socket researchers said the package names were crafted to resemble development tooling across crypto, DeFi, AI, and security workflows, targeting environments where cloud credentials, SSH keys, and wallet data may be stored on developer machines.

The firm described the campaign as a low-volume but high-impact operation, with a relatively small number of packages distributed across multiple registries but targeting environments containing high-value authentication and financial credentials.


0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

Wall Street giants to release financial reports next week: stock trading revenue expected to approach $19 billion, "everyone is a winner" may be a thing of the past

According to analyst expectations compiled by Bloomberg, the combined equity trading revenue of the five major U.S. banks in the third quarter will approach $19 billion, but fixed income trading revenue is expected to drop to its lowest point of the year, and M&A activity has also cooled. Meanwhile, AI-driven cash optimization tools may lead to deposit outflows, sparking concerns about bank stocks in the market. Analysts believe that while the profit performance of each bank may further diverge, market concerns about the impact of AI may be overblown.

华尔街见闻•2026/10/09 16:11