Solana, Sui and Aptos wallet data targeted in TrapDoor package attack

A supply-chain attack called TrapDoor deployed 34+ malicious packages across npm, PyPI and Crates.io, targeting Solana, Sui and Aptos developers. The disguised utilities steal wallet keys, SSH credentials, GitHub tokens and cloud access. Attackers also injected hidden instructions into AI configuration files to hijack coding sessions and exfiltrate secrets, marking a sophisticated shift toward developer-focused attacks rather than retail users.
Key takeaways
- 1TrapDoor supply-chain attack deployed 34+ malicious packages across npm, PyPI and Crates.io targeting Solana, Sui and Aptos developers.
- 2Malicious packages steal wallet keys, SSH credentials, GitHub tokens, AWS credentials and browser data from developer machines.
- 3Attackers injected hidden Unicode instructions into AI config files to hijack coding sessions and exfiltrate secrets automatically.
Coins in this story
Why it matters
Indian crypto developers face serious wallet theft and infrastructure compromise risks from sophisticated supply-chain attacks targeting open-source packages they trust. This marks a critical shift from retail user attacks to developer-focused threats, directly endangering India's growing blockchain and DeFi developer ecosystem.
Explore how AI Agents is shaping crypto markets — aggregated stories, leading coins, and weekly momentum.
Explore narrativeRelated stories

Bitcoin, ether little-changed despite record stocks, falling oil and easing war fears
Global stocks hit records and oil cracked on a tentative US-Iran ceasefire extension. Crypto stayed on the sidelines, with some analysts saying the next catalyst is regulatory, not geopolitical....

OKX Ventures buys $53 million stake in Korea's Coinone exchange
OKX Ventures and Korea Investment & Securities each invest KRW 80 billion ($53 million) for 19.6% stakes in South Korean exchange Coinone, pending regulatory approval. The combined $106 million deal marks a major global crypto firm investment into Korea's digital asset sector. Coinone CEO Cha Myunghun retains largest shareholder status at 27.8% and management control.
