TrapDoor Crypto Stealer Supply Chain Across NPM, PyPI, and Crates.io
Security researchers have identified TrapDoor, a crypto-stealing malware campaign operating across three major package registries: NPM, PyPI, and Crates.io. The malicious packages target cryptocurrency wallets by stealing sensitive data during installation, highlighting the ongoing risks of supply chain attacks in open-source ecosystems.