[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1-t6LNylPvP0VrodonEBoiyUZyEcqpikKUzR8JiRg_o":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":43},"8d77f64f-17df-4bcb-b1ff-5c83ab79c19c","hijacked-cicd-pipeline-injects-credential-stealing-malware-into-npm-and-pypi-packages","46cb7cc5-73c8-43f7-b70e-ea6ffcc8e1ae","Hijacked CI\u002FCD Pipeline Injects Credential-Stealing Malware into npm and PyPI Packages","Threat actors compromised MemTensor's GitHub Actions release pipelines to steal publish tokens, enabling them to inject a Go-based credential stealer (sckit) directly into legitimate, trusted packages on npm and PyPI. This supply chain attack is particularly dangerous because end users install packages they already trust, bypassing typical suspicion filters. The malware targets credentials across cloud platforms, code repositories, and developer tools — assets that can cascade into far broader organizational breaches. This incident highlights how CI\u002FCD pipeline secrets are high-value targets that, if left unprotected, can weaponize an entire package ecosystem against downstream consumers.","**Immediate actions:**\n- Audit and rotate all package registry publish tokens (npm, PyPI) and CI\u002FCD pipeline secrets immediately.\n- Remove or quarantine any recently published versions of MemTensor packages and scan developer environments for sckit indicators of compromise.\n- Enable two-factor authentication on all package registry accounts and source code management platforms.\n\n**Long-term improvements:**\n- Implement short-lived, OIDC-based publish tokens for CI\u002FCD pipelines instead of long-lived static secrets stored in environment variables.\n- Enforce code signing and provenance attestation (e.g., Sigstore\u002Fnpm provenance) for all published packages so consumers can verify authenticity.\n- Apply the principle of least privilege to CI\u002FCD pipeline permissions, scoping each workflow to only the permissions and secrets it strictly requires.\n\n**Detection measures:**\n- Monitor package registry activity for unexpected publish events, version bumps, or new maintainer additions outside of normal release windows.\n- Integrate software composition analysis (SCA) tools into developer pipelines to flag behavioral anomalies or unexpected dependencies in third-party packages.\n- Set up alerts for exfiltration patterns — such as outbound connections to unknown hosts — from developer workstations and build servers.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 4 – Secure Configuration of Enterprise Assets","CIS Control 6 – Access Control Management","CIS Control 16 – Application Software Security","NIST SP 800-161 – Supply Chain Risk Management","NIST SP 800-53 SA-12 – Supply Chain Protection","NIST SP 800-53 AC-6 – Least Privilege","NIST SP 800-53 IA-5 – Authenticator Management","SLSA Framework – Build Provenance and Supply Chain Integrity Levels","OpenSSF Scorecard – CI\u002FCD Pipeline Security Best Practices","ITIL – Change and Release Management Controls","published","2026-09-23T21:22:52.150961+00:00","2026-09-23T21:22:51.87+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fcompromised-memtensor-packages-deliver.html","compromised-memtensor-packages-deliver-sckit-credential-stealer-via-npm-and-pypi-344fcd","Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI",[31,37],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]