TrapDoor Cross-Ecosystem Crypto Stealer Campaign (opens in new tab)
TrapDoor is an active cross-registry supply-chain campaign using npm postinstall hooks, PyPI import-time execution, and Rust build scripts to steal developer, cloud, SSH, and crypto wallet secrets.
Read the original article