A malicious campaign dubbed TrapDoor is actively targeting developers in crypto, DeFi, AI, and security sectors with fake tooling packages. The goal? Steal cryptocurrency wallets, SSH keys, GitHub tokens, cloud credentials, and browser data. Wallet data from Solana, Sui, and Aptos is specifically being lifted, according to details of the attack.
How the fake packages work
The attackers are publishing counterfeit versions of legitimate developer tools and libraries. Unsuspecting developers install them thinking they're the real thing. Once inside a system, the malicious code silently exfiltrates sensitive files. The campaign is broad — it's not just crypto. But the crypto angle is hard to ignore: wallet private keys are a prime target.
What gets stolen
TrapDoor doesn't just go after one thing. The payloads grab SSH private keys, GitHub authentication tokens, cloud provider credentials, and saved browser data. For crypto devs, that means wallet seed phrases or key files stored locally are up for grabs. The attackers specifically target wallet data from the Solana, Sui, and Aptos ecosystems — suggesting they know exactly who they want to rob.
Why devs are in the crosshairs
Developers often hold the keys to the kingdom. They control deployment keys, smart contract admin wallets, and infrastructure secrets. A compromised dev machine can lead to a drained project treasury or a supply chain attack that affects users. TrapDoor is exploiting the trust developers place in package managers and open-source registries.
What comes next
No official statements from Solana, Sui, Aptos, or the affected package registries have surfaced yet. Researchers are urging developers to verify package signatures, check hashes against official sources, and avoid installing anything from unfamiliar names. The full scope of the campaign — how many packages are fake, how long it's been running — is still unclear.




