Key Takeaways:
On May 22, Socket found Trapdoor malware infecting 34 developer packages to steal crypto wallets and keys.Spanning 384 versions, the campaign tricks AI tools and severely impacts the development market.After a similar September attack, Socket warns developers must next secure AI environments from crypto theft.Dubbed Trapdoor, the supply chain attack spans 34 packages across these development environments, encompassing over 384 versions, with some still available. Socket reported that the affected packages were published in waves starting on May 22 and then were updated throughout the following weekend.
Socket stated that while this technique could not work consistently across all AI tools and models, its presence shows that attackers “are actively experimenting with AI development environments as part of supply chain malware campaigns.”


















