Cloud Security Alliance
TrapDoor Supply Chain Attack Analysis
Pages
11
Time to read
16 mins
Language
English
Pages
11
Time to read
16 mins
Language
English
This technical report documents the TrapDoor supply chain attack, which has disseminated over 34 malicious packages across multiple ecosystems, including npm, PyPI, and Crates.io. The attack specifically targets developers in the cryptocurrency and AI sectors, utilizing credential-stealing malware that exploits AI coding assistant configuration files. The report outlines the unique characteristics of TrapDoor, such as its use of hidden instructions embedded within configuration files that are processed by AI assistants without detection by developers. The malware is capable of harvesting a wide range of credentials, including SSH keys and API tokens, and employs various persistence mechanisms to maintain its presence. The report also details the campaign's timeline, the mechanisms of payload delivery, and the implications for organizations using AI coding assistants. It emphasizes the need for heightened security measures around AI context configuration files, treating them with the same scrutiny as build scripts and CI workflows.