TrapDoor / AuditorTrap crypto-stealer campaign across npm, PyPI and crates.io
Starting 2026-05-22 the TrapDoor / AuditorTrap campaign pushed 34+ malicious packages (384+ versions) across npm, PyPI and crates.io posing as crypto/DeFi/AI dev tools and fake "security guild" branding. Payloads steal SSH keys, cloud credentials and Solana/Sui/Aptos wallets, and hide zero-width-Unicode prompt injection in CLAUDE.md/.cursorrules to trick Claude Code and Cursor into running the stealer.
Versions named here: 0.5.0, 0.5.1, 0.5.2, 0.5.3, 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.6.4, 1.6.5, 1.6.6, 1.6.7, 1.6.8, 1.6.9, 4.0.0