It can be analyzed in just 58 seconds, and attackers are continuously updating; this attack and defense rhythm is even more exciting than DeFi mining.

View Original
MarsBitNews
Cryptocurrency theft program TrapDoor is actively attacking three major code repositories, with 34 malicious packages detected
Security company Socket Security discloses TrapDoor supply chain attacks, actively injecting malicious packages into repositories such as npm, PyPI, Crates.io, and others. A total of 34 malicious packages and 384 versions and components have been identified, with attackers continuously pushing new versions. TrapDoor targets developers in the cryptocurrency, DeFi, AI, and security fields, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, environment variables, and API keys. The median detection time is 5 minutes and 27 seconds, with the fastest detection occurring 58 seconds after a new version is released.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned