CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

TrapDoor

campaign · campaign:trapdoor single-source

Cross-ecosystem supply-chain campaign (npm / PyPI / Crates.io) featuring AI-assistant configuration poisoning.

Coverage
3
1 about it · 2 mentions · first 2026-05-26 → last 2026-06-01
Latest activity
2026-05-26
"TrapDoor" cross-ecosystem supply-chain campaign validates stolen tokens before exfil and poisons…
Peak priority
high
1 high
Targets
technology
sectors: technology, finance, public-sector · regions: europe
Sources cited
13
6 hosts
2026-05-263 appearances2026-06-01

Story timeline

Every entry that names TrapDoor, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.

  1. 2026-06-01Two concurrent npm dependency-confusion campaigns target internal corporate namespaces
    mentionactive-threats
  2. 2026-05-26"TrapDoor" cross-ecosystem supply-chain campaign validates stolen tokens before exfil and poisons AI-assistant config files
    active-threats
  3. 2026-05-26ACR Stealer distributed through counterfeit Claude AI download pages promoted by malicious search ads
    mentionactive-threats
ATT&CK techniques (11 across 6 tactics)

11 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessSupply Chain Compromise · Supply Chain Compromise: Compromise Software Dependencies and Development Tools · Supply Chain Compromise: Compromise Software Supply Chain
  • ExecutionScheduled Task/Job · Scheduled Task/Job: Cron · Command and Scripting Interpreter · Command and Scripting Interpreter: Unix Shell
  • PersistenceScheduled Task/Job · Scheduled Task/Job: Cron
  • Privilege EscalationScheduled Task/Job · Scheduled Task/Job: Cron
  • Credential AccessUnsecured Credentials · Unsecured Credentials: Credentials In Files
  • Lateral MovementRemote Services · Remote Services: SSH

Initial Access TA0001

T1195Supply Chain Compromise×1

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

T1195.001Supply Chain Compromise: Compromise Software Dependencies and Development Tools×1

Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications, such as pip and NPM packages, may be targeted as a means to add malicious code to users of the dependency. This may also include abandoned packages, which in some cases could be re-registered by threat actors after being removed by adversaries. Adversaries may also employ "typosquatting" or name-confusion by choosing names similar to existing popular libraries or packages in order to deceive a user.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

Execution TA0002

T1053Scheduled Task/Job×1

Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

T1059.004Command and Scripting Interpreter: Unix Shell×1

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

Persistence TA0003

T1053Scheduled Task/Job×1

Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

Privilege Escalation TA0004

T1053Scheduled Task/Job×1

Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

Credential Access TA0006

T1552Unsecured Credentials×1

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

Lateral Movement TA0008

T1021Remote Services×1

Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

T1021.004Remote Services: SSH×1

Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.

Evidence: 2026-05-26/trapdoor-cross-ecosystem-supply-chain-campaign-validates-sto · ATT&CK page ↗

Entries about TrapDoor (1)

2026-05-26 · view entry permalink →

HIGH

"TrapDoor" cross-ecosystem supply-chain campaign validates stolen tokens before exfil and poisons AI-assistant config files

Socket disclosed TrapDoor, a coordinated supply-chain campaign spanning 34+ malicious packages across 384+ versions published to npm, PyPI and Crates.io, with earliest activity on 2026-05-22 ~20:20 UTC; Socket reports a median detection latency of under six minutes after publish (Socket, 2026-05-24; The Hacker News, 2026-05-25). Each registry carries a distinct execution path: npm packages run a JavaScript credential harvester via a postinstall lifecycle hook (T1195.001, T1059.004); PyPI packages execute on import and pull a remote payload via node -e; Rust crates use build.rs scripts that XOR-encrypt local Sui/Solana/Aptos wallet keystores and exfiltrate them to GitHub Gists. The npm harvester validates stolen AWS and GitHub tokens against live APIs before flagging them; only working credentials are exfiltrated (T1552.001), and establishes persistence via cron, systemd units, Git hooks and SSH-based lateral movement (T1053.003, T1021.004). The defining novelty is an AI-assistant targeting vector: the packages write hidden instructions into .cursorrules and CLAUDE.md using zero-width Unicode characters (U+200B family), so a developer reviewing the file sees clean text while Cursor or Claude Code parses an attacker "security scan" directive that triggers data exfiltration (T1195.002).

Why it matters to us: the targeting (crypto/DeFi/AI developer communities) is narrow, but the execution model is not; any CH/EU public-sector DevOps pipeline that installs from these registries is exposed, and the AI-config-poisoning vector is a fresh class of persistence that survives a clean-looking code review. Hunt for node/python/cargo build processes spawning sh/bash/node -e, package-manager process trees writing to ~/.cursorrules or CLAUDE.md (especially with zero-width code points U+200B/U+200C/U+FEFF present), unexpected systemd unit or crontab writes from build runners, and GitHub Gist POST from CI. Pin exact versions, verify lockfile hashes, and run installs with --ignore-scripts where feasible.

threat26 May 05:00Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats3

Source distribution

  • attack.mitre.org8 (62%)
  • isc.sans.edu1 (8%)
  • microsoft.com1 (8%)
  • socket.dev1 (8%)
  • sonatype.com1 (8%)
  • thehackernews.com1 (8%)
All cited sources (13)