preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

security devops supply-chain open-source aws

TrapDoor Campaign Plants 34 Malicious Packages Across npm, PyPI, and Crates.io to Steal Cloud Credentials

A coordinated supply chain campaign called TrapDoor has deployed 34 malicious packages and more than 384 related versions across npm, PyPI, and Crates.io, targeting developers in crypto, AI, and security to steal AWS keys, GitHub tokens, SSH keys, and crypto wallets. The campaign also embeds hidden instructions in AI coding assistant configuration files to hijack Claude Code and Cursor sessions.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!