
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
The TrapDoor malware campaign targeted crypto and AI developers by distributing over 34 malicious packages across npm, PyPI, and Crates.io. It exploited AI coding assistants like Claude and Cursor via prompt injection, enabling theft of sensitive credentials, crypto wallet data, and cloud keys, causing significant harm to developer security.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (AI coding assistants Claude and Cursor) being hijacked by malware to perform malicious actions that result in theft of crypto assets and sensitive credentials. This constitutes direct harm to property and security, fulfilling the criteria for an AI Incident. The malware's use of AI to facilitate the attack and the realized harm from stolen data and crypto assets confirm this classification. The event is not merely a potential risk or a general update but a concrete incident involving AI system misuse causing harm.[AI generated]