Hijacked CI/CD Pipeline Injects Credential-Stealing Malware into npm and PyPI Packages
Threat actors compromised MemTensor's GitHub Actions release pipelines to steal publish tokens, enabling them to inject a Go-based credential stealer (sckit) directly into legitimate, trusted packages on npm and PyPI. This supply chain attack is particularly dangerous because end users install packages they already trust, bypassing typical suspicion filters. The malware targets credentials across cloud platforms, code repositories, and developer tools — assets that can cascade into far broader organizational breaches. This incident highlights how CI/CD pipeline secrets are high-value targets that, if left unprotected, can weaponize an entire package ecosystem against downstream consumers.
Tactical Insight
Immediate actions
- Audit and rotate all package registry publish tokens (npm, PyPI) and CI/CD pipeline secrets immediately.
- Remove or quarantine any recently published versions of MemTensor packages and scan developer environments for sckit indicators of compromise.
- Enable two-factor authentication on all package registry accounts and source code management platforms.
Long-term improvements
- Implement short-lived, OIDC-based publish tokens for CI/CD pipelines instead of long-lived static secrets stored in environment variables.
- Enforce code signing and provenance attestation (e.g., Sigstore/npm provenance) for all published packages so consumers can verify authenticity.
- Apply the principle of least privilege to CI/CD pipeline permissions, scoping each workflow to only the permissions and secrets it strictly requires.
Detection measures
- Monitor package registry activity for unexpected publish events, version bumps, or new maintainer additions outside of normal release windows.
- Integrate software composition analysis (SCA) tools into developer pipelines to flag behavioral anomalies or unexpected dependencies in third-party packages.
- Set up alerts for exfiltration patterns — such as outbound connections to unknown hosts — from developer workstations and build servers.