Targeted Attack on Developers Exposes Wallet and Credential Risks
- Security firm Socket identified a supply-chain attack named TrapDoor, affecting over 34 malicious packages across npm, PyPI, and Crates.io.
- The attack specifically targets developers, aiming to steal wallet files, SSH keys, GitHub tokens, and cloud credentials from their machines.
- Malicious packages were disguised as developer tools with names like “wallet-security-checker” and “defi-risk-scanner,” making them appear harmless.
- Payloads in the packages searched for private keys and left behind files to maintain access, turning normal installations into malware threats.
- Socket reported the malicious packages to the affected registries and noted attempts by attackers to contribute harmful code through pull requests.
This campaign highlights a shift in focus towards developers who possess sensitive information critical for crypto projects. The targeted nature of this attack emphasizes the growing sophistication of cyber threats within the cryptocurrency space.
With over three major registries compromised, the TrapDoor attack poses significant risks for developers handling wallet data and credentials on their systems. (Source)