TrapDoor Malware Exploits AI Coding Assistants to Steal Crypto and Credentials

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

The TrapDoor malware campaign targeted crypto and AI developers by distributing over 34 malicious packages across npm, PyPI, and Crates.io. It exploited AI coding assistants like Claude and Cursor via prompt injection, enabling theft of sensitive credentials, crypto wallet data, and cloud keys, causing significant harm to developer security.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system (AI coding assistants Claude and Cursor) being hijacked by malware to perform malicious actions that result in theft of crypto assets and sensitive credentials. This constitutes direct harm to property and security, fulfilling the criteria for an AI Incident. The malware's use of AI to facilitate the attack and the realized harm from stolen data and crypto assets confirm this classification. The event is not merely a potential risk or a general update but a concrete incident involving AI system misuse causing harm.[AI generated]
AI principles
Robustness & digital securitySafety

Industries
Digital security

Affected stakeholders
ConsumersWorkers

Harm types
Economic/Property

Severity
AI incident

Business function:
Research and development

AI system task:
Content generation


Articles about this incident or hazard

Thumbnail Image

TrapDoor Malware Targets Crypto Developer Tools

2026-05-25
Cointelegraph
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (AI coding assistants Claude and Cursor) being hijacked by malware to perform malicious actions that result in theft of crypto assets and sensitive credentials. This constitutes direct harm to property and security, fulfilling the criteria for an AI Incident. The malware's use of AI to facilitate the attack and the realized harm from stolen data and crypto assets confirm this classification. The event is not merely a potential risk or a general update but a concrete incident involving AI system misuse causing harm.
Thumbnail Image

TrapDoor Supply Chain Campaign Targets Developers Across Three Major Registries - Techiexpert.com

2026-05-25
Techiexpert.com
Why's our monitor labelling this an incident or hazard?
The event involves an AI system explicitly: AI coding assistants like Cursor and Claude are manipulated by the malware through hidden instructions embedded in configuration files. This manipulation leads to unauthorized system command execution, which is a direct cause of harm. The harm includes theft of sensitive credentials and digital wallets, which is harm to property and potentially to individuals and organizations. The malware's use of AI system manipulation to achieve these ends means the AI system's use is a contributing factor to the incident. Hence, this is an AI Incident rather than a hazard or complementary information.
Thumbnail Image

TrapDoor malware targets 34 crypto and AI packages

2026-05-25
COINTURK NEWS
Why's our monitor labelling this an incident or hazard?
The event involves AI systems explicitly through the exploitation of AI-powered developer assistants manipulated by prompt injection attacks. The malware's use of AI to bypass security checks and exfiltrate sensitive data directly leads to harm by compromising security credentials and access keys, which constitutes harm to property and potentially to communities relying on these systems. Therefore, this is an AI Incident because the AI system's misuse directly causes realized harm through data theft and security breaches.
Thumbnail Image

Socket Security Flags 34 Malicious Packages Striking Major Crypto Ecosystems - Crypto Economy

2026-05-25
Crypto Economy
Why's our monitor labelling this an incident or hazard?
The event explicitly involves AI systems (AI coding assistants Claude and Cursor) being manipulated through prompt injection to perform malicious workflows that steal secrets. This is a direct use of AI systems in the attack chain leading to realized harm (credential theft, exposure of private keys, and compromise of crypto infrastructure). The harm is materialized and significant, affecting property and communities within the crypto ecosystem. Therefore, this qualifies as an AI Incident because the AI system's use is pivotal in the harm caused.
Thumbnail Image

TrapDoor Malware Targets Crypto Dev Tools via npm, PyPI

2026-05-25
blockchain.news
Why's our monitor labelling this an incident or hazard?
The TrapDoor malware campaign involves AI-assisted methods to enhance its reach and effectiveness, including prompt injection attacks on AI coding assistants, which are AI systems. The campaign has directly led to theft of sensitive data and compromise of developer infrastructure, causing harm to property and communities in the crypto and AI sectors. The AI system's role is pivotal in both the malware's development and its exploitation of AI tools, fulfilling the criteria for an AI Incident rather than a hazard or complementary information.