Supply Chain Attack
TrapDoor Supply-Chain Attack Hits npm, PyPI, and Crates.io — and Poisons AI Coding Assistants
Socket disclosed TrapDoor, a coordinated attack that planted more than 34 malicious packages across npm, PyPI, and Crates.io at once. Its novel move: poisoned .cursorrules and CLAUDE.md files designed to trick a developer's AI coding assistant.