Compromised MemTensor Packages Distribute sckit Credential Stealer Through npm and PyPI
Threat actors compromised MemTensor packages on npm and PyPI to deploy a cross-platform Go-based credential-stealing implant called sckit, which harvests secrets from developer environments and cloud services. The attack involved stealing publish tokens through GitHub Actions and requires immediate mitigation steps like version pinning and domain blocking.
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.
According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below -
@memtensor/memos-cloud-openclaw-plugin versions
*** END OF TRANSMISSION ***