Hackers Use 34 Malicious Packages to Steal Cloud Keys, Wallets, and SSH Credentials

Hackers have planted 34 malicious packages across three major open-source ecosystems, quietly stealing cloud credentials, SSH keys, and blockchain wallet data from developers who never suspected a thing. The campaign, named TrapDoor, was first disclosed on May 24, 2026 by the security research team at Socket.dev, who found the poisoned packages spread across npm, PyPI, […]

The post Hackers Use 34 Malicious Packages to Steal Cloud Keys, Wallets, and SSH Credentials appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: