跳到正文
原文
@kimmonismus· @kimmonismus · X·· 2026-05-25精选AI 评分65
AI 导读

代号 TrapDoor 的供应链攻击同时针对 npm、PyPI 和 Crates.io,投递 34 个恶意包,目标是加密货币、AI 和安全开发者,用于窃取钱包、SSH 密钥和云凭证。

推荐理由

该攻击把 CLAUDE.md 与 .cursorrules 配置文件当作新入口,让安全从业者了解 AI 编程助手被利用的攻击路径。

正文

A coordinated supply chain attack called "TrapDoor" just hit npm, PyPI, and Crates. io simultaneously, 34 malicious packages targeting crypto, AI, and security developers to steal wallets, SSH keys, and cloud credentials.

New: attackers are also submitting pull requests to popular open-source repos, injecting manipulated CLAUDE.md and .cursorrules config files.

When a developer clones the repo and works with Claude Code or Cursor, the AI agent reads those files as trusted instructions, and could execute malicious commands without the developer realizing it.

Using AI assistants as the attack surface is new.

引用Socket (@SocketSecurity)@SocketSecurity
More analysis, package details, IOCs, and GitHub-related activity here, including attacker-hosted payload/config infrastructure and PRs attempting to add .cursorrules / CLAUDE.md files to popular AI and developer projects: socket.dev/blog/trapdoor-cry…
在 X 查看被引用的帖子

来源:@kimmonismus · x.com