TrapDoor Malware Hijacks AI Coding Tools to Steal Crypto Wallets and Developer Credentials
A sophisticated supply chain attack called TrapDoor has infiltrated npm, PyPI, and Crates.io with over 34 malicious packages designed to steal crypto wallets, SSH keys, and cloud credentials from developers. The campaign uses a novel technique to hijack AI coding assistants like Claude and Cursor, tricking them into executing hidden instructions that exfiltrate sensitive data.