Breach404
Back to Insights
Secure Software2 min readMay 25, 2026

TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

Attackers have compromised legitimate packages across major open-source repositories (npm, PyPI, and CratesIO) to distribute malware that steals credentials and sensitive information from developers and their systems. You should immediately audit your org

Could your website be vulnerable to attacks like this?

Run a free 10-point security scan on your site — headers, SSL, DNS, and more. Results in 15 seconds.

Test Your Site Now — It's Free