DeFi Security Threat: Malicious Packages Target Developers Through Common Workflows
A new cybersecurity threat targeting decentralized finance (DeFi) developers has emerged, with Socket's May 24 disclosure of TrapDoor uncovering more than 34 malicious packages across npm, PyPI, and Crates.io. These packages, spanning over 384 versions, exploit routine developer workflows to compromise credentials and infrastructure—posing a direct risk to protocol security and user funds.
The attack vector bypasses traditional code audits by leveraging standard developer actions: npm postinstall hooks, PyPI package imports, and Rust crate compilation scripts. TrapDoor's six-stage attack flow demonstrates how compromised developer machines can lead to credential theft, ultimately endangering on-chain assets. This campaign highlights the growing sophistication of supply chain attacks in crypto, where the human element—not just smart contract vulnerabilities—becomes the critical attack surface.
Log in to Reply
Log in to comment your thoughtsComments
Related Articles
|Square
Get the BTCC app to start your crypto journey
Get started today Scan to join our 100M+ users