Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Rather than blindly scooping up every AWS key and GitHub token it finds... the script actually makes live API calls first. It tests whether an AWS access key is active. It checks whether a GitHub personal access token (PAT) is still valid.
Human researchers observed the secondary payload deploying hidden embedded browsers that load malicious HTML5 domains and content behind the scenes, generating fake ad impressions, user clicks and ad bid requests without the user's knowledge.
Hackers have planted 34 malicious packages across three major open-source ecosystems... The campaign, named TrapDoor... found the poisoned packages spread across npm, PyPI, and Crates.io.
Once the organically downloaded app is launched, it serves fake pop-up alerts that mimic app update messages to trick users into installing the next-stage app.
The GitHub account ddjidd564 opened pull requests against six major AI and developer tooling repositories... Every PR was framed the same way: documentation improvements, adding developer standards... Reviewers looking at a diff would see what appears to be a helpful community contribution.
When you import one of the seven malicious PyPI packages, the __init__.py runs immediately which is standard Python behavior.
When you import one of the seven malicious PyPI packages, the __init__.py runs immediately... the import triggers a network request to ddjidd564.github.io, downloads a JavaScript file, and then spawns a local shell process to execute it using node -e.
Simply installing or building a package was enough to trigger the malicious code, with no further action required from the victim.
Rather than blindly scooping up every AWS key and GitHub token it finds... the script actually makes live API calls first. It tests whether an AWS access key is active. It checks whether a GitHub personal access token (PAT) is still valid.
When a developer runs npm install on any of the 21 identified malicious npm packages, a postinstall hook in the package’s package.json fires automatically... There’s no prompt, no warning, no user confirmation. The hook executes a payload file called trap-core.js.
Rather than blindly scooping up every AWS key and GitHub token it finds... the script actually makes live API calls first. It tests whether an AWS access key is active. It checks whether a GitHub personal access token (PAT) is still valid.
When a developer runs npm install on any of the 21 identified malicious npm packages, a postinstall hook in the package’s package.json fires automatically... There’s no prompt, no warning, no user confirmation. The hook executes a payload file called trap-core.js.
The files look blank or benign to a human reading them. But they’re loaded with hidden characters, zero-width spaces and bidirectional Unicode control characters, positioned precisely within the file.
This operation uses real, everyday software and multiple obfuscation and anti-analysis techniques - such as impersonating legitimate SDKs to blend in... | Users unwittingly download a threat actor-owned app, often a utility-style app like a PDF viewer or device cleanup tool.
Rather than blindly scooping up every AWS key and GitHub token it finds... the script actually makes live API calls first. It tests whether an AWS access key is active. It checks whether a GitHub personal access token (PAT) is still valid.
Trapdoor helps customers to create fake web pages and send phishing links to victims in order to trick them into revealing information, including passwords.
The system includes a “keylogger to record keystrokes, including potential capture of usernames and passwords.”
It checks whether a GitHub personal access token (PAT) is still valid... GitHub tokens. Personal access tokens with whatever scope the developer granted.
The stolen data included AWS keys, GitHub tokens, OpenAI API keys... and environment variables containing passwords or secrets.
The collection sweep targets... AWS access keys, secret access keys, and session tokens... .env files throughout the filesystem... Private keys, mnemonics, and any unencrypted keystore files in the home directory.
Before stealing anything, the script maps the host environment: what cloud providers are configured, what SSH keys exist, what browser profiles are present, what .env files are reachable.
the six malicious Crates.io packages... embed a build.rs that immediately scans the host filesystem for wallet keystores... Before stealing anything, the script maps the host environment... what .env files are reachable.
The malware also confirms where downloads originate from, enabling "malicious behavior only in users" who acquired apps "through threat actor-run ad campaigns." The operators behind the campaign suppressed organic downloads.
It scanned directories like .ssh, .aws, and .ethereum... targeting Sui, Aptos, and Solana wallet files... sweeping browser credentials, cloud keys, and wallet data across a broad set of file paths.
Trapdoor helps customers to create fake web pages and send phishing links to victims in order to trick them into revealing information, including passwords.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A supply chain malware operation distributing crypto-stealing packages and embedding persistence via shell profiles, Git hooks, cron jobs, AI tooling configurations, and SSH propagation logic.
An Android-based ad fraud and malvertising operation delivered through hundreds of malicious apps masquerading as benign utilities. It prompts users to install fake software updates as a second-stage payload, then deploys hidden embedded browsers to load malicious HTML5 content and generate fraudulent ad impressions, clicks, bid requests, and app installs while simulating realistic user behavior to evade detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.