Weekly review

ThreatNoir Afternoon Brief — September 23

2026-09-23Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 23, 2026

The afternoon of September 23, 2026 brings critical developments across supply chain security, privacy enforcement, and active zero-day exploitation. Organizations face immediate threats from compromised package repositories, regulatory action against major technology firms, and weaponized vulnerability chains actively deployed in the wild.

MemTensor npm and PyPI Packages Compromised in Credential-Stealing Supply Chain Attack

A sophisticated supply chain attack has compromised multiple releases of MemTensor packages across two major registries, affecting developers worldwide. The threat actor published malicious versions of the npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS, with each currently marked as the latest version on their respective registries. Source: Socket

The compromised releases bundle cross-platform Go binaries named sckit that execute automatically upon installation or import. The npm plugin versions 0.1.21, 0.1.23, and 0.1.25 launch the binary when the OpenClaw gateway starts and again on every memory recall operation. The PyPI package MemoryOS version 2.0.34 triggers execution as soon as the memos module is imported, requiring no explicit API call. The malicious code searches developer home directories for credentials including npm tokens, PyPI API tokens, GitHub and GitLab tokens, AWS access keys, Vault tokens, SSH keys, and environment variables containing sensitive information.

The attacker gained access to the legitimate publishing accounts and published the malicious releases without using the projects' CI workflows. Initial malicious commits appeared in MemTensor's GitHub repositories on September 23, 2026, with the npm releases following at 02:23 UTC and PyPI uploads at 05:25 UTC. The payload reports stolen credentials to command and control servers under the domain skyleen[.]fr, with separate C2 infrastructure for npm and PyPI campaigns. Organizations that loaded any of the three malicious npm versions or imported PyPI MemoryOS 2.0.34 should treat affected hosts as compromised, rotate all accessible secrets immediately, and block all connections to skyleen[.]fr and its subdomains.

Irish Data Protection Commission Fines Google €403 Million for Location Data Violations

The Irish Data Protection Commission has issued a substantial fine against Google following an investigation into the technology company's processing of location data. Source: European Data Protection Board

This enforcement action represents continued regulatory scrutiny of major technology firms' data handling practices and their compliance with GDPR requirements governing location information collection and processing.

Arista Urges Immediate Patching of Exploited VCO Zero-Day

Arista Networks has issued an urgent call for customers to patch a critical-severity zero-day vulnerability in its Virtual Cloud Orchestrator (VCO) platform that is actively being exploited in the wild. Source: SecurityWeek

The vulnerability, tracked as CVE-2026-93952, allows remote attackers to trigger the flaw and gain access to privileged internal functionality. The active exploitation status elevates this to a critical priority for organizations operating Arista infrastructure.

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor designated UTA0565 has been actively exploiting a chained zero-day vulnerability affecting Google Chrome and Microsoft Windows to deliver the CLEANGULP malware. Source: The Hacker News

The attacks, detected on September 3 and 4, 2026, leveraged two Chrome vulnerabilities (CVE-2026-85046 and CVE-2026-87491) combined with a Windows Advanced Local Procedure Call flaw (CVE-2026-85880) to achieve complete system compromise. The threat actor distributed malicious links through fake websites impersonating legitimate news and political organizations, including domains such as americanprgoress[.]top, chinadigitaltimes[.]top, and thecovnresation[.]com. This coordinated exploitation of unpatched vulnerabilities represents an active and ongoing threat to users who have not applied the latest security updates.

Today's threat landscape demands immediate action from organizations across multiple fronts: patching critical infrastructure vulnerabilities, auditing supply chain dependencies, and rotating compromised credentials while monitoring for indicators of breach activity.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

MemTensor npm and PyPI Packages Compromised in Credential-Stealing Supply Chain Attack
Domain1
  • skyleen[.]fr
    Command and control server domain
URL4
  • hxxps://[[.]]skyleen[[.]]fr//config
    C2 server endpoint
  • hxxps://[[.]]skyleen[[.]]fr//status
    C2 server endpoint
  • hxxps://[[.]]skyleen[[.]]fr//batch
    C2 server endpoint
  • hxxps://10729e014d0e[[.]]skyleen[[.]]fr/eb57efaa7365698fc1e4decc/initial-ci-v2
    PyPI CI helper endpoint
SHA-25614
  • f7c4014e284f…
    sckit binary for Windows ARM64 in PyPI package
  • f8ccdd1da7df…
    sckit binary for macOS ARM64 in npm packages
  • 56cd3416d2ec…
    sckit binary for Windows AMD64 in npm packages
  • d6b3e77c36ee…
    sckit binary for Windows ARM64 in npm packages
  • c1b0998347b4…
    sckit binary for Linux AMD64 in PyPI package
  • 8f647f17a193…
    sckit binary for Linux ARM64 in PyPI package
  • 9de0d5b0ca18…
    sckit binary for macOS AMD64 in PyPI package
  • 5405e3305076…
    sckit binary for macOS ARM64 in PyPI package
  • 16de381deb97…
    sckit binary for Windows AMD64 in PyPI package
  • 39ee64440682…
    PyPI distribution file: memoryos-2.0.34-py3-none-any.whl
  • 92b46d18fc55…
    PyPI distribution file: memoryos-2.0.34.tar.gz
  • 381ac6dc1715…
    sckit binary for Linux AMD64 in npm packages
  • e077c387b223…
    sckit binary for Linux ARM64 in npm packages
  • 65faf8ccbcf5…
    sckit binary for macOS AMD64 in npm packages
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
CVE3
Malware1
  • CLEANGULP
    Malware family deployed by threat actor
Domain3
  • chinadigitaltimes[.]top
    Fake website domain used for phishing
  • americanprgoress[.]top
    Fake website domain used for phishing
  • thecovnresation[.]com
    Command-and-control domain for CLEANGULP malware