TrapDoor opened today against 34 packages across npm, PyPI, and crates with hundreds of malicious versions designed to steal crypto wallets. Laravel-Lang turned out worse than first reported — Socket counts 700+ poisoned versions across four packages carrying an RCE backdoor, not just a credential stealer. Packagist disclosed eight Composer packages compromised through GitHub-Releases-hosted Linux malware, and Megalodon strafed 5,561 GitHub repos with malicious CI/CD workflows in a six-hour window.
The week-on-week pattern is the same: registry tokens stolen, version tags abused, GitHub Releases used as the dropper — which is why npm has now shipped 2FA-gated staged publishing in direct response to the Mini Shai-Hulud sweep that hit @antv last week. Underneath the narrative attacks, CISA catalogued three new actively-exploited CVEs (Drupal, Langflow, Trend Micro Apex One), and a fresh maximum-severity LiteSpeed cPanel plugin flaw (CVSS 10) is being weaponised in the wild. GitHub itself disclosed a separate internal-repo exfiltration by TeamPCP — adjacent to the package-hijack story but not part of it.