A coordinated campaign codenamed TrapDoor has infected npm, PyPI, and Crates.io ecosystems by distributing over 34 malicious packages designed to steal credentials.
A new, coordinated software supply chain attack, dubbed 'TrapDoor,' has targeted major package ecosystems including npm, PyPI, and Crates.io. The campaign aims to distribute credential-stealing malware across these platforms. The attack involves more than 34 malicious packages spanning over 384 versions. Initial activity was recorded on May 22, 2026, indicating a sophisticated effort to compromise software dependencies across the development landscape.