加密货币窃取程序 TrapDoor 正攻击三大代码仓库,34 个恶意软件包被检出

ChainCatcher 消息,安全公司 Socket Security 披露,一场名为 TrapDoor 的加密货币窃取活动正在 npm、PyPI 和 Crates.io 等软件包仓库中发起主动供应链攻击。目前已发现 34 个恶意软件包和 384 个版本及构件,攻击者持续在各生态系统中推送新版本。
TrapDoor 主要针对加密货币、DeFi、AI 和安全领域的开发者,窃取钱包、SSH 密钥、云凭证、GitHub 令牌、浏览器数据、环境变量和 API 密钥。Socket 检测到恶意版本的中位检测时间为 5 分 27 秒,最快检测发生在发布后 58 秒。
Disclaimer: OKX Orbit content is provided for informational purposes only. Learn more
Replies
Related Flash News
US media: The US and Iran are working to resolve their language differences on nuclear issues and sanctions
巨鲸nemorino.eth杠杆增持7,908.3枚ETH
YZi Labs launched the recruitment platform YZi Talent, integrating positions in its Web3, AI, and biotechnology portfolio
The Iranian delegation concluded its agenda in Qatar and will return to Tehran
ICON will officially shut down at the end of 2026, and the deadline for ICX to migrate to SODA is confirmed
A whale deposited 17.566 million ENA into Wintermute, losing about $3.6 million
Capital Macro: Even if the Middle East conflict ends in 2026, major economies still have no prospects of cutting interest rates
This week, macro data may dominate the crypto market, with PCE, unemployment claims, and housing data becoming key indicators for Fed rate cuts
On the eve of SpaceX's IPO, a $20 billion related-party transaction controversy emerged, and Musk's friend may use the IPO to rank among the top of the global billionaire list
Squid: Security incidents are unrelated to Squid's core protocols and contracts; all Squid users and integrators have not been affected


