← WeSearch · Blindspots
Full coverage · not a ranking

TrapDoor Supply Chain Campaign Targets npm, PyPI, and Crates.io to Poison AI Coding Agents

First seen May 24, 2026, 10:07 AM · latest May 25, 2026, 5:37 AM · free · no behavioral personalization
6Articles in sample
4Distinct publishers
0Wire-service items
0High-fact publishers

4 distinct publishers across 6 articles (some outlets filed more than once).

Ownership mix: Other: 6

What happened
🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.​io. Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly…

4 publishers · 6 articles · switch to 1-minute for disagreement and framing.

What happened

🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.​io. Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly…

Why the coverage differs

AI-assisted comparison · labeled · generated May 25, 2026, 12:35 PM · not a verdict

A supply chain attack known as "TrapDoor" has targeted package repositories npm, PyPI, and Crates.io, affecting 36 malicious packages primarily aimed at developers in the crypto, DeFi, AI, and security sectors. The attack reportedly involves the poisoning of AI coding assistants, which could lead to the dissemination of compromised code.

Coverage of the event is largely consistent across outlets, with most emphasizing the technical aspects of the attack and its implications for developers. However, some sources, like Socket, provide more detail on the specific types of packages affected and the potential risks to various sectors, while others, such as r/javascript, focus more on the AI-assistant poisoning angle. Overall, there is a lack of significant framing differences across the cluster, as most outlets maintain a neutral tone.

Comparison summary

AI-assisted · Cerebras / Llama · May 25, 2026, 12:35 PM · inspect sources below rather than trusting this alone

A supply chain attack known as "TrapDoor" has targeted package repositories npm, PyPI, and Crates.io, affecting 36 malicious packages primarily aimed at developers in the crypto, DeFi, AI, and security sectors. The attack reportedly involves the poisoning of AI coding assistants, which could lead to the dissemination of compromised code.

Coverage of the event is largely consistent across outlets, with most emphasizing the technical aspects of the attack and its implications for developers. However, some sources, like Socket, provide more detail on the specific types of packages affected and the potential risks to various sectors, while others, such as r/javascript, focus more on the AI-assistant poisoning angle. Overall, there is a lack of significant framing differences across the cluster, as most outlets maintain a neutral tone.

What remains unaddressed in this coverage is the response from the affected platforms or any measures being taken to mitigate the attack's impact. This absence leaves a gap in understanding how the repositories plan to protect their users and secure their systems against future threats.

How to read these numbers
Article count is not confirmation count. Wire rewrites and same-outlet follow-ups inflate totals. Prefer distinct publishers and primary links on each story page.

Report timeline

Oldest → newest among clustered members. Gaps may mean delayed pickup, not silence.

  1. May 24, 2026, 9:54 AM
  2. May 24, 2026, 9:59 AM
  3. May 24, 2026, 10:18 AM
  4. May 24, 2026, 11:34 AM
  5. May 24, 2026, 2:10 PM
  6. May 25, 2026, 5:30 AM

Headline framing

Vocabulary fingerprints · not a political endorsement

The headlines discuss a supply-chain attack named TrapDoor affecting npm, PyPI, and Crates.io, with a focus on its implications and targeting.

Per-source framing
Center
r-cybersecurity
TrapDoor supply-chain campaign hits npm, PyPI, and Crates.io with AI-assistant poisoning angle
supply-chainpoisoning
Focuses on the implications of the supply-chain attack.
Center
hn-newest
Active supply chain attack across NPM, PyPI, and Crates. io
supply chainattack
Highlights the ongoing nature of the supply chain attack.
Center
r-programming
TrapDoor supply-chain campaign targeted npm, PyPI, and Crates.io packages
supply-chaintargeted
Emphasizes the targeting aspect of the campaign.
Center
r-javascript
TrapDoor supply-chain campaign hits npm, PyPI, and Crates.io with AI-assistant poisoning angle
supply-chainpoisoning
Focuses on the implications of the supply-chain attack.
Center
hn-newest
TrapDoor supply chain attack hits PyPI, NPM, and crates.io
supply chainattack
Highlights the ongoing nature of the supply chain attack.
Center
r-programming
TrapDoor Supply Chain Campaign Targets npm, PyPI, and Crates.io to Poison AI Coding Agents
supply chaintargets
Emphasizes the targeting aspect of the campaign.

Bias/ownership: published methodology on source profiles · AI text always labeled · no reader paywall · no engagement ranking of news · transparency · contribute Ws · home