Skip to content
AI HOT (Curated Pool)

TrapDoor Supply Chain Attack Makes AI Assistants a New Attack Surface

TrapDoor供应链攻击:AI助手成新型攻击面

TrapDoor hit npm, PyPI, and Crates.io with 34 malicious packages, using manipulated CLAUDE.md and .cursorrules files in pull requests to make Claude Code and Cursor treat attacker content as trusted instructions and run malicious commands.

Why it matters: HKR-H/K/R all pass: AI coding assistants become the execution surface, with 34 malicious packages across three registries. Single-post sourcing lacks IOCs, timeline, and victim scale, so this stays in the 78–84 band.

Read the original ↗Export Markdown