New supply chain attack on 34 packages, 100 versions on NPM, PyPI and crates.io
Researchers discovered a new supply chain attack targeting 34 packages across NPM, PyPI, and crates.io, with over 100 malicious versions published. The packages deploy a "TrapDoor" crypto stealer designed to exfiltrate cryptocurrency wallet credentials and sensitive data from infected systems.