‘TrapDoor’ malware targets crypto dev tools in supply chain attack

Read original at CoinTelegraph·

‘TrapDoor’ malware targets crypto dev tools in supply chain attack

60-second summary

Malicious actors are unleashing a campaign of "TrapDoor" malware, targeting crypto development tools in a supply chain attack, with Socket warning of stolen crypto and hijacked popular AI coding assistants, including GitHub Copilot and Kite. The malware injects hidden instructions to siphon sensitive data, putting developers and their projects at risk of severe financial loss.

Socket says a campaign of malicious packages is aiming to steal crypto and is injecting hidden instructions that hijack popular AI coding assistants.