Socket Security has revealed that the TrapDoor theft program is conducting supply chain attacks on major code repositories, including npm, PyPI, and Crates.io. The campaign involves 34 malicious packages and 384 versions and artifacts, specifically targeting developers in the cryptocurrency, DeFi, AI, and security sectors. The attacks aim to steal sensitive information such as wallets, SSH keys, cloud credentials, and GitHub tokens.
The median detection time for these malicious versions is 5 minutes and 27 seconds, with the fastest detection recorded at just 58 seconds. This rapid detection highlights the ongoing efforts to mitigate the impact of such attacks on developers and their projects.
TrapDoor Stealer Targets npm, PyPI, and Crates.io with Malicious Packages
免責事項: Phemexニュースで提供されるコンテンツは、あくまで情報提供を目的としたものであり、第三者の記事から取得した情報の正確性・完全性・信頼性について保証するものではありません。本コンテンツは金融または投資の助言を目的としたものではなく、投資に関する最終判断はご自身での調査と、信頼できる専門家への相談を踏まえて行ってください。
