TrapDoor is a financially motivated software supply chain threat activity cluster focused on stealing cryptocurrency-related assets and secrets from developer environments. It has been observed distributing malicious crypto-stealing packages through multiple open-source package ecosystems, including npm, PyPI, and crates.io, indicating a cross-platform approach to compromising developer trust paths and downstream build environments. The activity aligns with opportunistic abuse of software distribution channels to reach developers and organizations through trusted package installation workflows. TrapDoor is notable for combining package-based initial access with multiple persistence and propagation mechanisms inside developer systems. Reported persistence methods include modification of shell profiles, abuse of Git hooks, scheduled tasking through cron, tampering with AI tooling configurations, and SSH-based propagation logic. This indicates an emphasis on maintaining access after package execution and extending compromise across adjacent developer assets and repositories. The operation is associated with crypto-stealing behavior rather than ransomware or destructive extortion. Its tradecraft centers on initial access via trojanized packages, theft of credentials and cryptocurrency-related material, persistence within developer workstations and tooling, and post-compromise propagation through trusted development workflows. Known alias usage includes trapdoor_operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Distributed crypto-stealing packages across multiple package ecosystems and used persistence and propagation mechanisms to maintain access and spread.
Distributed crypto-stealing packages across npm, PyPI, and crates.io with persistence and propagation mechanisms aimed at developer environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.