Security researchers have flagged an active malware campaign dubbed TrapDoor, targeting developer environments across multiple blockchain ecosystems — including Solana, Aptos, and Sui. The campaign appears designed to compromise developer toolchains, package managers, or SDK integrations, giving attackers a foothold in the build pipeline rather than attacking end-user wallets directly.
Supply-chain attacks on developer environments are particularly dangerous in crypto because a single compromised package or CLI tool can propagate malicious code across dozens of downstream projects and thousands of end-user wallets before detection. Targeting three distinct ecosystems simultaneously suggests a well-resourced threat actor with broad knowledge of blockchain development stacks.
TheBlock