[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftnPNexTQTROx7viJFbOaUxuNh5jvgcVqT_4u9Kpf4mM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"3fdb4f6b-224e-47ad-b03a-135a5ebc3184","malicious-npmpypi-packages-steal-developer-credentials-in-memtensor-supply-chain-attack","c458a35c-6ac8-445f-bb50-4169b5d08e1a","Malicious npm\u002FPyPI Packages Steal Developer Credentials in MemTensor Supply Chain Attack","Threat actors hijacked MemTensor's MemOS open-source packages on npm and PyPI to distribute malicious versions bundling a hidden Go binary designed to harvest secrets from developer environments. This attack is particularly dangerous because developers inherently trust packages from familiar project namespaces, making malicious updates an effective delivery mechanism. Exfiltrated credentials spanning AWS, GitHub, GitLab, SSH, and package registry accounts can cascade into further infrastructure compromises far beyond the initial victim. Supply chain attacks of this nature exploit the implicit trust in the open-source ecosystem, making verification and monitoring of third-party dependencies a critical security control.","**Immediate actions:**\n- Audit all projects using MemTensor npm and PyPI packages and rotate any credentials that may have been exposed to affected environments.\n- Remove or pin dependency versions to known-good, verified releases and re-audit lockfiles for unexpected package updates.\n- Scan developer workstations and CI\u002FCD environments for the malicious Go binary and indicators of compromise associated with this campaign.\n\n**Long-term improvements:**\n- Implement a software composition analysis (SCA) tool in CI\u002FCD pipelines to automatically flag newly published or updated third-party packages before installation.\n- Enforce least-privilege secrets management by storing credentials in dedicated vaults (e.g., HashiCorp Vault, AWS Secrets Manager) rather than in plaintext developer directories.\n- Establish a verified internal package mirror or artifact repository to control and vet which external packages are permitted in your build environment.\n\n**Detection measures:**\n- Monitor outbound network connections from developer machines and build servers for anomalous traffic to unknown command-and-control endpoints.\n- Enable alerting on bulk file reads of known credential locations (e.g., ~\u002F.npmrc, ~\u002F.aws\u002Fcredentials, ~\u002F.ssh) by unexpected processes.\n- Subscribe to security advisories from PyPI, npm, and GitHub Advisory Database to receive timely notification of compromised packages.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Cybersecurity Supply Chain Risk Management","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 SI-3: Malicious Code Protection","SLSA Framework: Supply-chain Levels for Software Artifacts","GDPR Article 32: Security of Processing (for organizations handling EU data)","OWASP A06:2021 – Vulnerable and Outdated Components","published","2026-09-23T12:22:35.791141+00:00","2026-09-23T12:22:35.496+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fmemtensor-compromise?utm_medium=feed","memtensor-npm-and-pypi-packages-compromised-in-credential-stealing-supply-chain--65a27e","MemTensor npm and PyPI Packages Compromised in Credential-Stealing Supply Chain Attack",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[48],{"id":49,"date":50,"edition":51,"title":52,"audio_url":53},"9afea3bd-f321-49a8-b827-3e00ffa57a8a","2026-09-23","afternoon","ThreatNoir Afternoon Brief — September 23","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-23\u002Fthreatnoir-afternoon-brief-2026-09-23.mp3"]