A May 24 disclosure by Socket revealed a supply chain attack called TrapDoor, which planted over 34 malicious packages and 384 related versions across npm, PyPI, and Crates.io — three of the most widely used developer package repositories. The campaign targets DeFi protocol developers directly, harvesting credentials and creating pathways from a single compromised developer machine into the broader infrastructure of live protocols. Because the attack occurs at the development stage, malicious code could reach production before security audits detect it, meaning exploits may be initiated long before a protocol is publicly deployed. The TrapDoor findings highlight a growing vulnerability in DeFi's security model, where smart contract audits alone are insufficient if the developer environment itself has been silently compromised upstream.
— Sponsored —
Trade smarter on BYDFI
Get a bonus on your first deposit — from $50 at $100, up to $2,000 at $20k. 200x leverage, 600+ perpetuals, deep liquidity.