Socket researchers identified 34 malicious packages spanning 384 versions across npm, PyPI, and Crates.io in a coordinated supply chain campaign. The malware, named TrapDoor, steals SSH keys, crypto wallet data, and cloud credentials targeting developers on Coinbase, Solana, and Sui.