Close Menu
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
What's Hot

The Massive Supply Chain Attack Targeting Crypto Developers

May 26, 2026

Aave and Kelp DAO Opens Full Operations for rsETH Tokens

May 26, 2026

Chris Larsen XRP wallets go active near midterms

May 25, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
CatchTheBullCatchTheBull
Bitcoin

The Massive Supply Chain Attack Targeting Crypto Developers

By WebDeskMay 26, 20262 Mins Read
The Massive Supply Chain Attack Targeting Crypto Developers
Share
Facebook Twitter LinkedIn Pinterest Email

Key Takeaways

  • On May 22, Socket found Trapdoor malware infecting 34 developer packages to steal crypto wallets and keys.
  • Spanning 384 versions, the campaign tricks AI tools and severely impacts the development market.
  • After a similar September attack, Socket warns developers must next secure AI environments from crypto theft.

Supply Chain Attack Scheme Trapdoor Targets Developers For Maximum Performance

While some malware campaigns target everyday crypto users, others focus on developers, aiming to capture targets with a higher chance of holding large amounts of cryptocurrency and having access to broader resources.

Researchers at Socket, a company that specializes in preventing supply chain attacks, have identified a broad campaign targeting crypto developers using infected packages across npm, PyPI, and Crates.io.

Dubbed Trapdoor, the supply chain attack spans 34 packages across these development environments, encompassing over 384 versions, with some still available. Socket reported that the affected packages were published in waves starting on May 22 and then were updated throughout the following weekend.

The packages stood out due to their nature, as they allegedly represented generic developer tools and appeared in quick succession across different registries. This gives the campaign “broad reach across adjacent developer communities where crypto wallets, cloud credentials, Github tokens, and SSH keys are likely to be present,” socket assessed.

The infected packages invade the development environment of crypto developers, leveraging these alleged open-source tools, taking hold of secrets, crypto wallets, secure shell (SSH) keys, and other relevant data.

Trapdoor infected packages also try to leverage AI tools to collaborate with their attack, using directive files to trick AI coding tools to run a security scan and exfiltrate highly sensitive data.

Socket stated that while this technique could not work consistently across all AI tools and models, its presence shows that attackers “are actively experimenting with AI development environments as part of supply chain malware campaigns.”

Chain attacks are becoming more common. In September, the crypto community was alerted about a similar hack, with several packages used by crypto wallets being compromised and modified to steal cryptocurrency funds from wallets containing bitcoin, ether, and solana, among other digital assets.

Credit: Source link

Previous ArticleAave and Kelp DAO Opens Full Operations for rsETH Tokens

Related Posts

Chris Larsen XRP wallets go active near midterms

May 25, 2026

How To Play The Bitcoin 4-Year Cycle For The Most Gains In The Bull Market

May 25, 2026

Why Questions Are Being Raised about The XRP Ledger’s 300,000 Milestone

May 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

The Massive Supply Chain Attack Targeting Crypto Developers

May 26, 2026

Aave and Kelp DAO Opens Full Operations for rsETH Tokens

May 26, 2026

Chris Larsen XRP wallets go active near midterms

May 25, 2026

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

Advertisement Banner

Welcome to CatchTheBull, your trusted source for the latest Crypto News and Airdrops. We bring you real-time updates, expert insights, and opportunities to stay ahead in the crypto world. Discover trending projects, market analyses, and airdrop details all in one place.

Join us on this journey to navigate the ever-evolving blockchain universe!

Facebook X (Twitter) Instagram YouTube
Top Insights

Is $20 Actually Within Reach This Cycle?

What Markets Can You Access Through a CFD Trading Account?

Here’s Why Bitcoin Price is at Risk of Massive Long Squeeze

Get Informed

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

© 2026 CatchTheBull. All Rights Are Reserved.
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$76,531.00-0.63%
  • ethereumEthereum(ETH)$2,086.15-0.43%
  • tetherTether(USDT)$1.000.02%
  • binancecoinBNB(BNB)$657.630.31%
  • rippleXRP(XRP)$1.33-0.79%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$83.83-1.30%
  • tronTRON(TRX)$0.3737432.49%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.00%
  • dogecoinDogecoin(DOGE)$0.100669-1.12%
  • HyperliquidHyperliquid(HYPE)$58.80-4.49%
  • USDSUSDS(USDS)$1.000.00%
  • zcashZcash(ZEC)$626.03-3.36%
  • leo-tokenLEO Token(LEO)$10.00-0.49%
  • cardanoCardano(ADA)$0.240081-0.40%
  • moneroMonero(XMR)$377.63-4.37%
  • bitcoin-cashBitcoin Cash(BCH)$344.930.08%
  • chainlinkChainlink(LINK)$9.37-0.29%
  • whitebitWhiteBIT Coin(WBT)$56.30-0.70%
  • CantonCanton(CC)$0.164447-0.17%
  • the-open-networkToncoin(TON)$1.906.90%
  • stellarStellar(XLM)$0.1476450.45%
  • USD1USD1(USD1)$1.000.00%
  • Ethena USDeEthena USDe(USDE)$1.000.03%
  • daiDai(DAI)$1.000.00%
  • suiSui(SUI)$1.02-0.35%
  • litecoinLitecoin(LTC)$52.16-0.80%
  • avalanche-2Avalanche(AVAX)$9.180.22%
  • MemeCoreMemeCore(M)$2.993.36%
  • RainRain(RAIN)$0.0080295.79%
  • hedera-hashgraphHedera(HBAR)$0.086975-1.40%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.01%
  • nearNEAR Protocol(NEAR)$2.7015.02%
  • shiba-inuShiba Inu(SHIB)$0.000006-0.87%
  • crypto-com-chainCronos(CRO)$0.067946-1.20%
  • Circle USYCCircle USYC(USYC)$1.130.00%
  • Global DollarGlobal Dollar(USDG)$1.00-0.01%
  • tether-goldTether Gold(XAUT)$4,516.50-0.60%
  • BittensorBittensor(TAO)$275.381.33%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.13-0.57%
  • pax-goldPAX Gold(PAXG)$4,524.55-0.58%
  • mantleMantle(MNT)$0.64-0.91%
  • polkadotPolkadot(DOT)$1.24-0.48%
  • uniswapUniswap(UNI)$3.27-2.78%
  • OndoOndo(ONDO)$0.410881-6.40%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.0606150.55%
  • HTX DAOHTX DAO(HTX)$0.0000021.21%
  • okbOKB(OKB)$86.143.54%
  • AsterAster(ASTER)$0.68-2.00%