A coordinated malware campaign dubbed TrapDoor distributed 34 malicious packages across 384 artifact versions on npm, PyPI, and Crates.io, targeting developers working with crypto/DeFi tools and AI coding assistants. The packages harvested SSH keys, AWS credentials, GitHub tokens, browser profiles, and cryptocurrency wallet keystores. Notably, the campaign embedded hidden instructions in .cursorrules and CLAUDE.md project files using zero-width Unicode characters, so that when a developer opened an infected project in Cursor or Claude Code, the AI assistant’s own automated project scan would trigger exfiltration of local secrets.