← Radar

Incident case file

Sign in to watch

TrapDoor — Cross-Ecosystem Supply-Chain Credential-Theft Campaign (npm + PyPI + Crates.io)

Incident date May 22-28, 2026

0 views

ActivenpmPyPICrates.ioSupply chain / AI agent prompt injectionCluster: TRAP-SCM-2026-05

Estimated loss

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Attacker: GitHub account ddjidd564 (C2 host ddjidd564.github.io); npm account asdxzxc; internal campaign marker P-2024-001. No on-chain attacker address (credential-theft campaign, not an on-chain drain).

Funds moved to: Not applicable / not quantifiable. TrapDoor exfiltrates developer credentials (SSH keys, browser sessions, AWS credentials, crypto wallet keystores, API tokens) for downstream theft; no aggregate USD figure has been published and no single on-chain destination exists.
Off-chain indicators of compromise rather than wallets. GitHub account: ddjidd564 (payload host ddjidd564.github.io). npm account: asdxzxc. Internal marker: P-2024-001. Shared npm payload: trap-core.js (~48,485 bytes credential harvester). Crates.io XOR key string: cargo-build-helper-2026. Earliest malicious upload: PyPI package eth-security-auditor@0.1.0 on 22 May 2026 20:20:18 UTC. Representative malicious packages: git-config-sync, token-usage-tracker, sui-framework-helpers, dev-env-bootstrap

Timeline: TrapDoor is a coordinated cross-ecosystem supply-chain credential-theft campaign spanning npm, PyPI and Crates.io, plus AI-coding-assistant context poisoning. The earliest known malicious package, PyPI eth-security-auditor@0.1.0, was uploaded on 22 May 2026 at 20:20:18 UTC, followed by waves across npm (postinstall hooks), PyPI (import-time execution) and Crates.io (build.rs). The malware steals SSH keys, browser session data, AWS credentials, crypto wallet keystore files and API tokens, and persists via Git hooks, shell hooks, systemd, cron and SSH. A distinctive vector is AI-coding-assistant poisoning: the campaign plants .cursorrules and CLAUDE.md files containing zero-width Unicode payloads that trick Cursor and Claude Code into performing hostile credential exfiltration under the guise of running an automated security scan. Socket disclosed the campaign on 24 May 2026 (blog + X), and SlowMist published an in-depth analysis on 28 May 2026 (advisory SM-2026-352284), characterising it as one of the largest cross-ecosystem supply-chain poisoning attacks observed since 2026. Affected developers must rotate all credentials, remove compromised packages, and scan for the P-2024-001 marker, the ddjidd564.github.io domain, the trap-core.js file and packages from npm user asdxzxc. No aggregate USD theft figure is available; the impact is measured in compromised developer environments (Rescana estimates 35,000+ potentially exposed repositories). The campaign was still active at the cutoff, with continued re-uploads.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)