Curated by

J

JD Audena

stacklist.com/jdaudena

life’s better when it’s bold, curious, and a little chaotic | building & becoming always | in service of the future | fellow omnipotentialite and friend to @KyleHudson

More from JD Audena

See all stacks →

TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack

TrapDoor crypto stealer is a supply chain attack that compromised 36 malicious packages across npm, PyPI, and Crates.io, targeting developers working in crypto, DeFi, AI, and security. The attack, discovered by the Socket Research Team, affected hundreds of package versions across multiple open-source ecosystems.

View card
Built for AI agentsACO · 80 tokens

Summary

TrapDoor crypto stealer is a supply chain attack that compromised 36 malicious packages across npm, PyPI, and Crates.io, targeting developers working in crypto, DeFi, AI, and security. The attack, discovered by the Socket Research Team, affected hundreds of package versions across multiple open-source ecosystems.

Tags

supply-chain-attack · crypto-stealer · npm · pypi · crates-io · malware · open-source-security

Key entities

TrapDoor Crypto Stealer (concept, 0.98) · Socket Research Team (organization, 0.95) · npm (technology, 0.97) · PyPI (technology, 0.97) · Crates.io (technology, 0.97) · supply-chain attack (concept, 0.98) · DeFi (concept, 0.85)

Classification

analysis · language en · status final

Provenance

claude-opus-4-6 via @stacklist/mcp-server@2.0.0, confidence 0.85, 26 May 2026