Researchers Detail 'TrapDoor' Supply‑Chain Attack That Hid Malicious Instructions in AI Assistant Files
Security researchers say 'TrapDoor' used malicious npm, PyPI and Crates.io packages to target crypto wallets and developer credentials, hiding commands in AI assistant files.