TrapDoor Supply Chain Attack Credential Stealer | MSSP Advisory
HighCredible Report
DateMay 25, 2026
📋Executive Summary
A coordinated supply chain attack called TrapDoor compromised 34 malicious packages across npm, PyPI, and Crates.io package repositories starting May 22, 2026. The campaign distributes credential-stealing malware through 384+ package versions targeting developers who pull dependencies from these ecosystems. Attack vectors span JavaScript, Python, and Rust development environments.
⚠️Why It Matters for MSSPs
Your development teams likely pull packages from npm, PyPI, or Crates.io daily, making your internal tooling and client delivery systems direct targets for credential theft. Every client running applications built with dependencies from these repositories faces potential compromise, and you need to audit both your own development stack and advise clients on their exposure immediately.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Supply Chain
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.