Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› TrapDoor Supply Chain Campaign 2026: How 34 Malicious…
Breach analysis Incident: 24 May 2026

TrapDoor Supply Chain Campaign 2026: How 34 Malicious Packages Hunted Developer Credentials and Tried to Turn AI Coding Assistants Into Accomplices

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
On this page

On 24 May 2026, Socket disclosed TrapDoor, a coordinated campaign that published more than 34 malicious packages and over 384 versions across npm, PyPI and Crates.io from 22 May. The packages posed as developer, security and crypto tools. Once installed, they hunted for SSH keys, AWS credentials, GitHub tokens, browser data and crypto wallets, and the npm payload checked stolen AWS and GitHub credentials against live APIs to see which still worked. TrapDoor also aimed at AI coding assistants. It planted .cursorrules and CLAUDE.md files carrying hidden instructions, written with zero-width Unicode characters, meant to make tools such as Cursor and Claude Code run a fake "security scan" that would find and send out secrets. The same operator opened pull requests proposing such files to popular AI projects including LangChain and browser-use. Socket flagged the packages within minutes. No victims or download figures have been published.

Key takeaways

  • Socket found more than 34 malicious packages and 384 versions on npm (21 packages), PyPI (7) and Crates.io (6), the first uploaded on 22 May 2026, posing as developer and DeFi tooling.
  • Each registry used its own trigger: npm install hooks, code that runs on import in Python and build.rs scripts that run when Rust code compiles.
  • The npm payload stole SSH keys, cloud credentials and GitHub tokens, tested AWS and GitHub credentials through API calls and tried to reuse SSH keys to reach other machines.
  • TrapDoor tried to poison AI coding assistants with hidden instructions in .cursorrules and CLAUDE.md, and pull requests to AI projects tested whether such files would be accepted. Socket says the technique may not work consistently, and no victims have been reported.
  • The identity lesson: an AI coding assistant acts with the developer's credentials, so any file it reads as instructions becomes part of the attack surface for those credentials.

At a glance

OrganisationsDevelopers in crypto, DeFi, Solana, Sui and AI communities using npm, PyPI and Crates.io; AI projects targeted with pull requests, including browser-use, LangChain, Langflow, LlamaIndex, MetaGPT and OpenHands
WhenFirst package uploaded 22 May 2026; disclosed by Socket on 24 May 2026; waves continued over that weekend
AttackerUnknown. Socket links the activity to a cluster of registry accounts and a GitHub account but makes no wider attribution
Entry pointNew malicious packages published by attacker-controlled accounts, plus pull requests proposing AI assistant instruction files
Identities abusedTargeted: developers' SSH keys, AWS credentials, GitHub tokens and API keys; AI coding assistants such as Cursor and Claude Code acting with the developer's access
ImpactLive credential-stealing packages on three registries; no confirmed victims, downloads or losses reported
CategoryNHI, Agentic AI and AI agents. Incident class: AI-agent incident or attempt (credential stealers and AI assistant poisoning attempts in the wild; no confirmed victims)

What happened

The first TrapDoor package, eth-security-auditor on PyPI, was uploaded at 20:20 UTC on 22 May 2026, according to Socket. Over the weekend a handful of accounts published waves of packages with names such as dev-env-bootstrapper, wallet-security-checker and sui-move-build-helper. Socket's research team counted 21 npm packages, 7 on PyPI and 6 on Crates.io, with more than 384 related versions and artefacts.

The packages ran code in whatever way each registry allowed. On npm, an install hook ran a shared payload called trap-core.js. On PyPI, importing the package downloaded JavaScript from the attacker's GitHub Pages site and ran it, so the attacker could change behaviour without a new release. On Crates.io, build.rs scripts searched for wallet keystores during compilation and sent them to GitHub Gists. Socket found the npm payload collected SSH keys, AWS credentials, GitHub tokens, browser profiles, environment variables and API keys. "The npm malware also validates stolen AWS and GitHub credentials using API calls," it wrote, and the malware tried to use stolen SSH keys for lateral movement.

The unusual part was the attempt to recruit AI coding assistants. Among its persistence methods, the npm payload wrote .cursorrules and CLAUDE.md files, which Cursor and Claude Code read as project instructions. "In this campaign, the attacker attempts to plant hidden instructions using zero-width Unicode characters," Socket said. The aim was to get the assistant to run a "security scan" that would discover secrets and send them out. Socket added that "This technique may not work consistently across all tools or models". Separately, a GitHub account tied to the campaign opened pull requests against browser-use, LangChain, Langflow, LlamaIndex, MetaGPT and OpenHands proposing similar files. GitHub warned that the browser-use file contained hidden or bidirectional Unicode text. Socket believes the operator was "testing whether AI-facing project files can be introduced through normal open source contribution workflows."

Socket said it detected the package versions with a median time of 5 minutes 27 seconds after publication, classified them all as malicious and reported them to the registries. A planning file in the attacker's repository described a "Universal AI Agent Extraction Framework", which Socket says was only partly implemented. Cyber Security News and SOCRadar reported the campaign on 25 May, and GitGuardian included it in a June round-up of four credential-harvesting campaigns. SOCRadar noted that "Public reporting does not establish a definitive victim list or quantified losses".

Timeline

DateEvent
22 May 2026The first TrapDoor package, eth-security-auditor, is uploaded to PyPI at 20:20 UTC; more waves follow over the weekend.
24 May 2026Socket publishes its analysis of TrapDoor and reports the packages to the registries.
25 May 2026Cyber Security News and SOCRadar report on the campaign.
3 June 2026GitGuardian lists TrapDoor among four credential-harvesting campaigns in two weeks.

How it happened: the identity attack path

  1. Lures published. Attacker accounts published new packages that looked like developer, security and DeFi tools on three registries.
  2. Code runs with the developer's identity. Installing, importing or building a package ran the payload with the developer's own permissions.
  3. Credentials harvested and tested. The npm payload collected SSH keys, AWS credentials and GitHub tokens and checked them against live APIs.
  4. Movement and persistence. Stolen SSH keys were used to try to reach other systems, and persistence was set up through Git hooks, shell hooks, cron and systemd.
  5. AI assistants targeted. Hidden instructions in .cursorrules and CLAUDE.md, and pull requests to AI projects, tried to make coding assistants find and send out secrets on the attacker's behalf.

Impact

  • Confirmed: more than 34 credential-stealing packages and 384 versions were published on npm, PyPI and Crates.io. Socket detected most within minutes; how long each stayed available has not been reported.
  • Not reported: download counts, victims and losses. No compromise of a real organisation has been publicly linked to TrapDoor.
  • Attempted: pull requests to at least six AI projects proposing assistant instruction files; Socket does not report any being merged.
  • Potential: any developer who installed a TrapDoor package should treat SSH keys, cloud credentials, GitHub tokens and wallet keys on that machine as stolen, and check for planted assistant instruction files.

What this means for NHI and AI agent security

TrapDoor targeted the identities developers carry: SSH keys, cloud keys, GitHub tokens and wallet keys. Its new twist was treating the AI coding assistant as another way to reach them. Tools such as Cursor and Claude Code, run by developers on their own machines, read files like .cursorrules and CLAUDE.md as trusted guidance and act with the developer's access. No one had to change the assistants' safeguards for this to be a risk; the attacker only needed to get a file into the project. Socket found the attack and says it may not work reliably, but it shows how agent instruction files are becoming part of the supply chain.

Teams should treat agent instruction files as code, review them in pull requests, and limit what an assistant can read and run. Keeping long-lived credentials off developer machines reduces what any of these routes can steal. See our AI Coding Agents Security Guide and AI Supply Chain and AI-BOM Guide.

Recommendations

  • Review agent instruction files like code. Require review for changes to CLAUDE.md, .cursorrules and similar files, and scan them for hidden or bidirectional Unicode. See our AI Coding Agents Security Guide.
  • Limit what coding assistants can run. Require approval for shell commands and network calls, and run assistants in sandboxes without access to production credentials. See our Zero Trust for AI Agents Guide.
  • Keep long-lived keys off developer machines. Use short-lived cloud credentials, SSH certificates and a secrets manager instead of keys in home directories and environment variables. See our Secrets Management Guide.
  • Vet new packages before installing. Use a package firewall or a cooldown for newly published packages, and block install-time scripts where possible.
  • Rotate credentials after any suspect install. Revoke SSH keys, cloud keys and GitHub tokens from affected machines and look for new Git hooks, cron jobs and systemd units. See the Leaked Credential Response Playbook.

Frequently asked questions

What is the TrapDoor supply chain attack?

TrapDoor is a May 2026 campaign of more than 34 malicious packages on npm, PyPI and Crates.io, disclosed by Socket on 24 May 2026. The packages posed as developer and crypto tools and stole SSH keys, cloud credentials, GitHub tokens and wallet data from machines that installed them.

How did TrapDoor target AI coding assistants?

It planted .cursorrules and CLAUDE.md files containing instructions hidden with zero-width Unicode characters, meant to make assistants such as Cursor and Claude Code run a fake security scan that would collect secrets. It also opened pull requests proposing such files to AI projects including LangChain and browser-use.

Did TrapDoor compromise anyone?

No victims, download counts or losses have been published. Socket detected the packages within minutes of publication on average and reported them to the registries, and says the AI assistant technique may not work consistently. Anyone who installed one of the packages should still rotate their credentials.

Sentry MCP Agentjacking 2026 · Laravel-Lang Composer Compromise 2026 · ClawHub Malicious Skills 2026 · AI Coding Agents Security Guide · AI Supply Chain and AI-BOM Guide

How NHI Mgmt Group can help

AI coding assistants inherit every credential on the developer's machine. We help teams govern what those assistants can read and run, review the instruction files they trust and move developer credentials to short-lived alternatives. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org