supply-chain TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO A sophisticated supply chain attack, dubbed TrapDoor, is spreading credential-stealing malware across npm, PyPI, and Crates.io, targeting developers in the crypto, DeFi, Solana, and AI communities. The attack utilizes a multi-faceted approach, including malicious packages with JavaScript payloads, Rust crates for data… The Hacker News · May 25, 2026 High USsupply-chaincredential-stealingdeveloper-workflow