[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQKm_vTM9Y5gZLg66t6nV2Whf8PyhRi_6VhzjDV4JP54":3},{"article":4,"iocs":53},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"46cb7cc5-73c8-43f7-b70e-ea6ffcc8e1ae","Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI","compromised-memtensor-packages-deliver-sckit-credential-stealer-via-npm-and-pypi-344fcd","Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor\u002Fmemos-cloud-openclaw-plugin versions","Unknown threat actors compromised legitimate MemTensor packages on npm and PyPI, injecting a Go-based implant named sckit. This cross-platform malware targets Windows, Linux, and macOS, stealing credentials from cloud services, code platforms, and developer tools. The attackers gained access by exploiting MemTensor's GitHub Actions release pipelines to steal publish tokens.","Compromised MemTensor npm and PyPI packages deliver sckit credential stealer.","Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI Ravie LakshmananSep 23, 2026Malware \u002F Cloud Security Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor\u002Fmemos-cloud-openclaw-plugin versions 0.1.21, 0.1.23 and 0.1.25 (versions 0.1.22 and 0.1.24 are clean) MemoryOS version 2.0.34 (project currently quarantined on PyPI) The malicious npm package versions include a \"hidden Go payload into a legitimate AI memory integration. Versions 0.1.21, 0.1.23, and 0.1.25 contain code that launches the payload when the agent gateway starts and whenever the plugin handles a memory-recall event,\" StepSecurity said. \"The launcher passes the host process environment and, during recall, the user's prompt text directly to the malicious executable.\" The PyPI package, on the other hand, starts the statically-linked Go binary as soon as the \"memos\" module is imported into an application. Regardless of the ecosystem targeted, the end goal is to launch a cross-platform credential-stealing payload capable of harvesting sensitive data from cloud services, source-code platforms, package registries, and developer tools and exfiltrating the details to an external server (\"skyleen[.]fr\"). According to Socket, targets include npm, PyPI, GitHub, GitLab, AWS, Vault and SSH secrets - Credential files (.npmrc, .vault-token, id_ecdsa, credentials.db, access_tokens.json and stored_tokens) Environment variables that indicate tokens, passwords, API keys, private keys, session cookies and database or message-broker connection strings (e.g., NPM_TOKEN and PYPI_API_TOKEN) AWS access keys, GitHub and GitLab tokens, npm and PyPI tokens, Hugging Face, HashiCorp Vault, Slack, Stripe and SendGrid keys, and JWTs SafeDep, in its analysis of the supply chain attack, said the attacker obtained the publish tokens from MemTensor's own GitHub Actions release pipelines by pushing commits that caused the workflow to hand over the npm or PyPI token. A deeper examination of the implant suggests that it can function like a worm by self-proliferating through GitHub and direct npm and PyPI package publishing. As of writing, it's unclear if there are packages other than MemTensor that are impacted by the compromise. \"It collects credentials from developer machines and from CI jobs,\" SafeDep said. \"It receives signed tasks from a command-and-control (C2) server. It also contains templates to install itself in npm packages, Python packages, and GitHub Actions workflows.\" Given that the malicious versions of the npm packages are still available for download, it's essential to pin the packages to a safe baseline version (0.1.20 for the npm package, 2.0.33 for the PyPI package), rotate exposed secrets, kill any sckit process, and block \"skyleen[.]fr\" and all its subdomains. \"The MemOS Cloud plugin connects the OpenClaw agent runtime to a memory service,\" StepSecurity said. \"Its normal work includes recalling relevant memories before an agent processes a prompt and adding memories after a run. The package also declares integration points for the Clawdbot and Moltbot runtimes.\" \"This places the plugin inside a process that routinely handles user input and may inherit valuable credentials. On a developer workstation, the same user account can have access to cloud configuration, source repositories, package publishing tokens, and application secrets. In automation, the process may receive credentials injected for a particular job.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cloud security, Malware, Open Source Security, Supply Chain ⚡ Top Stories This Week Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. How to Evaluate a Unified Security Platform Using a One-Incident Test Stop Trying to Control AI Behavior. Control What AI Can Reach ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fcompromised-memtensor-packages-deliver.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEhFThFSFsti-2SIka75bNuMKpyJHtOW2ZPrZtcSjbjFQ64GCNn0WtdssYuWlVTbhaLB5cAJ0vu8FgyNmNsDa8g0Ijy-D1zP4FW7ihVfAjk9xWMYDMMdfZPICGyVdjeDwH3-jyKLHOUnjfaXBJIMxGn_3ngeXFsbb4CLnOibRd4fbwXHYpBkMQTcBQAf0edq\u002Fs1600\u002Fnpm-pypi.jpg","2026-09-23T13:52:46+00:00","2026-09-23T20:00:12.699043+00:00",9,[18,21,23,26,28],{"name":19,"type":20},"@memtensor\u002Fmemos-cloud-openclaw-plugin","product",{"name":22,"type":20},"MemoryOS",{"name":24,"type":25},"npm","technology",{"name":27,"type":25},"PyPI",{"name":29,"type":25},"Go","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":30,"icon":32,"name":33,"slug":34},null,"Supply Chain","supply-chain",[36,38,43,48],{"category":37},{"id":30,"icon":32,"name":33,"slug":34},{"category":39},{"id":40,"icon":32,"name":41,"slug":42},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":44},{"id":45,"icon":32,"name":46,"slug":47},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":49},{"id":50,"icon":32,"name":51,"slug":52},"c70f3a41-2f0c-4608-870d-b8cbcd8be076","Cloud Security","cloud-security",[54],{"type":55,"value":56,"context":57},"domain","skyleen.fr","Command and control server for sckit implant."]