HomeNewsHackers Target Aptos, Sui, and Solana Developers With TrapDoor Malware Campaign

Hackers Target Aptos, Sui, and Solana Developers With TrapDoor Malware Campaign

- Advertisement -
  • Researchers discover 34 malicious packages from TrapDoor malware targeting Aptos, Sui, and Solana ecosystems.
  • The packages are designed to steal developers’ crypto wallets, SSH keys, cloud credentials, browser data, and environment variables

Researchers from Socket Security have issued a warning to communities in the Aptos, Sui, and Solana ecosystems. A new malware called TrapDoor is targeting these ecosystems by injecting malicious packages into code repositories like npm, PyPI, and Crates.io. Hiding in applications like AI assistant files and automation scripts, the malware can steal crypto wallets, cloud tokens, and access keys from developer workstations.

The researchers noted that the earliest releases of the malware were observed on Friday at 20:20 UTC, with more published in quick succession, suggesting the attack was coordinated, not opportunistic. The TrapDoor malware was built to search compromised computers for sensitive data, including SSH keys, AWS credentials, GitHub tokens, browser login data, API keys, and crypto wallet files associated with Sui, Solana, and Aptos development environments.

Crypto users and platforms have been targeted by malware campaigns before. Scammers have used phishing emails and fake downloads for years, and now they are widening the net to include builders. Crypto wallets, cloud credentials, and AI tooling make these developers good targets.

TrapDoor Manipulates AI Tools

One of the most unusual aspects of the TrapDoor campaign was its attempt to manipulate AI coding assistants. The attackers added hidden instructions into files commonly used by AI development tools. Those instructions attempted to convince AI assistants to perform fake “security scans” that would expose sensitive local files and credentials.

Socket noted that the malware used zero-width Unicode characters to conceal some of these instructions from human review while still making them readable to certain AI systems.

As AI-assisted coding accelerates software development, companies are increasingly relying on open-source dependencies, automated package installations, and AI-generated workflows. This means they are now vulnerable to attacks designed for this convenience.

Socket’s platform is now calling on developers in the affected ecosystems to run tests to detect this malicious malware. Its detection systems identified TrapDoor releases within minutes of publication across multiple registries. It further noted that it has classified all identified packages as malicious and continues to track and report on related versions and infrastructure associated with the campaign.

As ETHNews reported in March, another report recently identified a similar security threat. OX Security has identified a widespread phishing campaign targeting developers who interact with OpenClaw, an open-source AI agent project with 324,000 GitHub stars, using fake token airdrop offers to drain crypto wallets and steal SSH credentials.

Security has become a major concern for crypto this year, with nearly a dozen exploits draining close to $1 billion from DeFi protocols. Cross-chain bridges have been the most common target, leading to a migration from LayerZero bridging to more secure alternatives such as Chainlink’s CCIP. Over $4 billion in crypto assets have moved to Chainlink in the past month alone.

Disclaimer: ETHNews does not endorse and is not responsible for or liable for any content, accuracy, quality, advertising, products, or other materials on this page. Readers should do their own research before taking any actions related to cryptocurrencies. ETHNews is not responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods, or services mentioned.
Collin Brown
Collin Brown
Collin Brown is the managing partner of ETHNews. He is a seasoned Bitcoin investor who entered the crypto scene during its early stages and has since become a veteran trader in both the cryptocurrency and forex markets. His journey began in 2012 when he made his first investment in Bitcoin, marking the beginning of his deep-rooted passion for blockchain technology and digital assets. With a mission to demystify the intricacies of blockchain for the masses, Collin endeavors to bring the world of cryptocurrencies closer to everyone. His insightful reports are dedicated to shedding light on the latest developments and innovations within the realms of Bitcoin, Ethereum, Ripple (XRP), IOTA, VeChain, Cardano, Hedera, and numerous other cryptocurrencies. Marcel's in-depth analysis and commitment to providing accessible information make him a trusted source for both novice and experienced crypto enthusiasts. Collin's academic background includes a Master's Degree in Business Education, which has equipped him with a solid foundation in financial markets and investment strategies. Over the past decade, he has amassed invaluable experience working with various startups across the globe, enriching his knowledge and understanding of the ever-evolving cryptocurrency landscape. With his wealth of expertise and dedication to empowering others with crypto knowledge, Collin continues to be a driving force in the cryptocurrency community.
RELATED ARTICLES

LATEST ARTICLES