TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

2026-05-25T07:24:08Z2986c6515ed400210a4a1594b9d053de0c35590770d1dbd69acac1f30fe3445f
ci-cd-misusecrates.iocredential-stealergitHubincident-responseknown-exploited-vulnerabilitieslaravel-langlaw-enforcement-takedownmalicious-extensionmalware-signing-abusenpmpackagistpypisupply-chainthreat-actor-activity

What happened

A wave of high-impact supply-chain and infrastructure incidents: a coordinated cross-ecosystem supply-chain campaign dubbed “TrapDoor” is distributing credential-stealing malware via npm, PyPI and Crates.io (34 malicious packages across ~384 versions, first observed May 22, 2026). Multiple other package repositories were hit (Laravel-Lang PHP packages, Packagist), and GitHub suffered large-scale automated CI/CD injection (Megalodon) plus an internal-repo breach via a poisoned Nx Console VS Code extension. Several actively exploited and high-severity flaws were disclosed or added to CISA KEV (e

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
2986c6515ed400210a4a1594b9d053de0c35590770d1dbd69acac1f30fe3445f
Enrichment time
2026-05-25T07:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.