Close Menu
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Facebook X (Twitter) Instagram
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Cryphedge.com
Home » TrapDoor Malware Targets Solana, Sui and Aptos Developers
TrapDoor Malware Targets Solana, Sui and Aptos Developers

TrapDoor Malware Targets Solana, Sui and Aptos Developers

May 31, 20266 Mins ReadNo Comments NFT News
Share
Facebook Twitter LinkedIn Pinterest Email

A new malware campaign named TrapDoor is targeting developers within crypto, DeFi, and AI ecosystems, including Solana, Sui, and Aptos. According to Socket Security (Socket) and the Cloud Security Alliance (CSA), this campaign has distributed over 34 malicious packages with 384 versions/artifacts across npm, PyPI, and Crates.io since at least May 22, 2026, aiming to steal wallet files, developer credentials, and other secrets on developers’ machines. This data could pave the way for attackers to compromise private repositories, cloud infrastructure, or development wallets of related projects.

What Happened

TrapDoor is described as a software supply chain attack campaign targeting developer environments, rather than a direct exploit against Solana, Sui, or Aptos. Attackers publish fake packages to popular registries commonly used by developers. These packages are named similarly to legitimate tools like security scanners, wallet checkers, build utilities, or AI tooling, making them easy to be installed during the development process.

According to Socket, TrapDoor has appeared on npm, PyPI, and Crates.io with over 34 malicious packages and more than 384 associated versions/artifacts. CSA stated that this group of packages includes 21 packages on npm, 7 packages on PyPI, and 6 packages on Crates.io. The first confirmed package was [email protected], uploaded to PyPI on May 22, 2026, at 20:20:18 UTC, while some infrastructure indicators suggest that preparation activities may have begun as early as May 19, 2026.

TrapDoor Malware Targets Solana, Sui and Aptos Developers

Token-usage-tracker marked as known malware by Socket. Source: Socket.

These packages target developers because their work devices often contain many valuable credentials, ranging from SSH keys, GitHub tokens, and cloud credentials to wallet keystores or private keys used for development.

How the Attack Works

TrapDoor operates by hiding malicious code inside packages that developers might download while building applications. When a package is installed or called within a project, the malicious code can execute automatically without any obvious signs to the user. This is why attacks through package registries are often dangerous: they exploit the very workflow that developers are familiar with.

According to Socket, TrapDoor packages can execute in different ways depending on the platform. On npm, the malware can be triggered immediately after the package is installed. On PyPI, it can run when a developer imports the package in Python. With Crates.io, the malicious code can execute during the compilation of a Rust project.

Once active, TrapDoor scans the developer’s machine for access keys, login tokens, browser data, and wallet-related files. Socket noted that certain credentials, including AWS and GitHub tokens, are even validated against real APIs before being exfiltrated, showing that the attackers prioritize access rights that are still valid. If these credentials are exposed, attackers can move from the developer’s machine to the project’s repositories, servers, CI/CD pipelines, or cloud accounts.

Why This Case Matters

What sets TrapDoor apart from many previous package malware campaigns is that it reaches into workflows using AI coding assistants. According to the Cloud Security Alliance, the malware can install or modify files such as .cursorrules and CLAUDE.md, which are used by Cursor, Claude Code, and similar tools to read instructions within a project.

These files can contain hidden instructions using Unicode characters that are nearly invisible to users, but are still read as text by AI assistants. In some cases, these instructions can prompt the AI tool to suggest or execute actions disguised as a “security scan,” but actually aimed at harvesting secrets on the developer’s machine.

Socket and CSA also recorded that attackers attempted to open pull requests to several open-source AI projects, including LangChain, Langflow, browser-use, llama_index, MetaGPT, and OpenHands, aiming to introduce malicious configuration files into repositories through documentation contributions. These pull requests were detected and closed, with no signs of successful merging.

Impact on Solana, Sui and Aptos

As of May 31, 2026, there are no public reports confirming that TrapDoor has caused specific financial losses or directly compromised the protocols of Solana, Sui, or Aptos. Current findings indicate that the primary target is the developer work environment within these ecosystems.

However, the risk remains significant because developers often have deep access to project infrastructure. A compromised development machine could pave the way for attackers to access the codebase, deployment systems, or wallets used for testing, deploying, and operating applications. With crypto projects, an exposed GitHub token or cloud key could be enough for attackers to modify code, plant backdoors, or pivot to other systems.

Solana, Sui, and Aptos are ecosystems with highly active developer communities, with a frequent need to use SDKs, packages, wallet tooling, and build tools during application development. This makes fake packages look more “contextually correct” when targeting specialized developer groups, rather than just distributing mass malware across registries.

For ecosystems with many SDKs, packages, wallet tooling, and build tools, fake packages can look more familiar in the developer workflow, especially when named similarly to tools serving application development.

What Developers Should Do

Developers who have installed suspicious packages from May 19–22, 2026, onward need to review new dependencies from npm, PyPI, or Crates.io, especially those masquerading as crypto, security, or AI tools. The inspection should also extend to AI configuration files in projects such as .cursorrules, CLAUDE.md, or AGENTS.md, as this is a notable part of the TrapDoor campaign.

If an unusual package or configuration file is detected, the next step is to check Git history, scan the machine, and rotate critical access keys. For developers who have installed packages on the malicious list, associated tokens, cloud credentials, and wallet keys should be replaced immediately, even if no clear signs of exfiltration have been observed yet.

For Solana, Sui, and Aptos developers, the severity lies in the access rights that development machines usually hold, from tooling and test keys to infrastructure serving applications. When these permissions are exposed, the impact can extend beyond individual machines and affect the projects being built or operated.

Disclaimer NFTPlazas provides trusted news and insights on Web3. The views expressed on this site do not constitute investment advice. Before making any high-risk investments in cryptocurrency or digital assets, please conduct your own thorough research. All transfers and transactions are carried out at your own risk, and any resulting losses are solely your responsibility. NFTPlazas does not endorse the buying or selling of cryptocurrencies or digital assets and is not a licensed investment advisor. Please also note that NFTPlazas may participate in affiliate marketing programs.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
cryphedge

Related Posts

CZ Wants to Make the U.S. the ‘Capital of Crypto’

June 29, 2026

SharpLink Purchases 39,196 ETH Worth $62.4 Million After Eight-Month Pause

June 29, 2026

Bitwise Stakes $114 Million in HYPE on Hyperliquid as Its Spot ETF Doubles Down

June 28, 2026

Coinbase and OKX Chase Binance Users as MiCA Deadline Bites

June 28, 2026
Add A Comment

Comments are closed.

Editors Picks

XRPL ReservedTxns: Schwartz’s Anti-Front-Running Fix

June 30, 2026

JPMorgan warns rushed US crypto rules could create market loopholes as Senate races toward July CLARITY Act vote

June 30, 2026

Pi Network Expand Into Real-World Business With PiVerif

June 30, 2026

XRP Price Today: XRP At $1.05

June 30, 2026
About

cryphedge is an online news portal that aims to share the latest crypto news, bitcoin, altcoin, blockchain, nft news, regulation, trading, crypto scams and much more stuff.

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

MEXC launches STORY (IP) launchpool & airdrop+, offering 68,500 IP & 50,000 USDT in bonuses

February 12, 2025

The Hidden Catalyst That Could Push Solana (SOL) and Ethereum (ETH) to New Highs – A Mid-Term Price Prediction

June 12, 2025

TRUMP memecoin drops to all-time low as team dumps $32M token

March 12, 2026
Subscribe
Please enable JavaScript in your browser to complete this form.
Loading
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$58,459.00-2.14%
  • ethereumEthereum(ETH)$1,567.14-0.68%
  • tetherTether(USDT)$1.000.00%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • binancecoinBNB(BNB)$545.27-1.03%
  • rippleXRP(XRP)$1.04-1.28%
  • solanaSolana(SOL)$73.43-0.57%
  • tronTRON(TRX)$0.316397-2.04%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.052.33%
  • HyperliquidHyperliquid(HYPE)$65.180.61%
  • dogecoinDogecoin(DOGE)$0.070755-2.70%
  • RainRain(RAIN)$0.015737-1.65%
  • USDSUSDS(USDS)$1.000.02%
  • leo-tokenLEO Token(LEO)$9.19-2.22%
  • zcashZcash(ZEC)$402.193.18%
  • stellarStellar(XLM)$0.1829415.36%
  • moneroMonero(XMR)$304.16-1.60%
  • CantonCanton(CC)$0.1463330.92%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$46.56-2.51%
  • cardanoCardano(ADA)$0.144499-0.64%
  • chainlinkChainlink(LINK)$7.17-1.96%
  • USD1USD1(USD1)$1.000.00%
  • daiDai(DAI)$1.00-0.01%
  • Ethena USDeEthena USDe(USDE)$1.000.00%
  • LABLAB(LAB)$13.31-14.26%
  • Gram (prev. Toncoin)Gram (prev. Toncoin)(GRAM)$1.54-4.41%
  • bitcoin-cashBitcoin Cash(BCH)$200.462.26%
  • litecoinLitecoin(LTC)$41.73-1.79%
  • Circle USYCCircle USYC(USYC)$1.13-0.06%
  • hedera-hashgraphHedera(HBAR)$0.070213-1.39%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • avalanche-2Avalanche(AVAX)$6.51-2.05%
  • suiSui(SUI)$0.69-0.12%
  • PayPal USDPayPal USD(PYUSD)$1.000.01%
  • shiba-inuShiba Inu(SHIB)$0.000004-0.23%
  • tether-goldTether Gold(XAUT)$4,022.470.15%
  • crypto-com-chainCronos(CRO)$0.053353-0.99%
  • nearNEAR Protocol(NEAR)$1.79-2.86%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.13-0.30%
  • BittensorBittensor(TAO)$202.80-0.39%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.057649-0.27%
  • pax-goldPAX Gold(PAXG)$4,025.210.16%
  • uniswapUniswap(UNI)$2.76-6.59%
  • AsterAster(ASTER)$0.620.61%
  • okbOKB(OKB)$78.620.27%
  • OndoOndo(ONDO)$0.309815-0.63%
  • HTX DAOHTX DAO(HTX)$0.000002-2.44%
  • WorldcoinWorldcoin(WLD)$0.414867-1.62%
  • Falcon USDFalcon USD(USDF)$0.990.00%
  • Ripple USDRipple USD(RLUSD)$1.000.01%
  • polkadotPolkadot(DOT)$0.82-0.76%
  • mantleMantle(MNT)$0.416576-1.60%
  • usddUSDD(USDD)$1.000.00%
  • BFUSDBFUSD(BFUSD)$1.000.00%
  • aaveAave(AAVE)$85.41-5.62%
  • SkySky(SKY)$0.0537734.28%
  • Pi NetworkPi Network(PI)$0.113215-3.31%
  • MorphoMorpho(MORPHO)$1.884.37%
  • internet-computerInternet Computer(ICP)$2.11-2.00%
  • bitget-tokenBitget Token(BGB)$1.61-0.91%
  • ethereum-classicEthereum Classic(ETC)$6.97-0.90%
  • DeXeDeXe(DEXE)$23.197.35%
  • United StablesUnited Stables(U)$1.000.02%
  • PepePepe(PEPE)$0.000002-1.31%
  • Blockchain CapitalBlockchain Capital(BCAP)$106.970.00%
  • quant-networkQuant(QNT)$64.31-1.63%
  • ​​Stable​​Stable(STABLE)$0.0386071.89%
  • Spiko EU T-Bills Money Market FundSpiko EU T-Bills Money Market Fund(EUTBL)$1.200.04%
  • kucoin-sharesKuCoin(KCS)$6.73-1.48%
  • MemeCoreMemeCore(M)$0.6820.39%
  • Janus Henderson Anemoy Treasury FundJanus Henderson Anemoy Treasury Fund(JTRSY)$1.110.01%
  • Invesco Short Duration US Government Securities FundInvesco Short Duration US Government Securities Fund(USTB)$11.130.03%
  • USDGOUSDGO(USDGO)$1.00-0.02%
  • kaspaKaspa(KAS)$0.0303898.60%
  • AudieraAudiera(BEAT)$2.79-0.15%
  • cosmosCosmos Hub(ATOM)$1.53-0.58%
  • render-tokenRender(RENDER)$1.51-3.11%
  • POL (ex-MATIC)POL (ex-MATIC)(POL)$0.069204-2.76%
  • algorandAlgorand(ALGO)$0.082516-3.70%
  • USDtbUSDtb(USDTB)$1.00-0.02%
  • justJUST(JST)$0.085797-0.49%
  • nexoNEXO(NEXO)$0.720.46%
  • ADIADI(ADI)$5.551.36%
  • JupiterJupiter(JUP)$0.208613-2.43%
  • 币安人生 (BinanceLife)币安人生 (BinanceLife)(币安人生)$0.69-2.90%
  • gatechain-tokenGate(GT)$6.42-0.85%
  • Janus Henderson Anemoy AAA CLO FundJanus Henderson Anemoy AAA CLO Fund(JAAA)$1.040.02%
  • BeldexBeldex(BDX)$0.087566-1.84%
  • VelvetVelvet(VELVET)$1.58-5.99%
  • EthenaEthena(ENA)$0.070591-12.19%
  • Spiko Amundi Overnight Swap Fund (EUR)Spiko Amundi Overnight Swap Fund (EUR)(EURSAFO)$1.15-0.05%
  • GHOGHO(GHO)$1.000.01%
  • Venice TokenVenice Token(VVV)$12.68-1.63%
  • Pump.funPump.fun(PUMP)$0.001427-1.70%
  • filecoinFilecoin(FIL)$0.72-0.74%
  • YLDSYLDS(YLDS)$1.000.00%
  • xdce-crowd-saleXDC Network(XDC)$0.0279340.49%
  • Usual USDUsual USD(USD0)$1.000.00%
  • FlareFlare(FLR)$0.006380-2.27%