Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News by The Hacker News
September 23, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananSep 23, 2026Malware / Cloud Security

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.

According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below –

The malicious npm package versions include a “hidden Go payload into a legitimate AI memory integration. Versions 0.1.21, 0.1.23, and 0.1.25 contain code that launches the payload when the agent gateway starts and whenever the plugin handles a memory-recall event,” StepSecurity said.

“The launcher passes the host process environment and, during recall, the user’s prompt text directly to the malicious executable.”

The PyPI package, on the other hand, starts the statically-linked Go binary as soon as the “memos” module is imported into an application.

Regardless of the ecosystem targeted, the end goal is to launch a cross-platform credential-stealing payload capable of harvesting sensitive data from cloud services, source-code platforms, package registries, and developer tools and exfiltrating the details to an external server (“skyleen[.]fr”).

According to Socket, targets include npm, PyPI, GitHub, GitLab, AWS, Vault and SSH secrets –

  • Credential files (.npmrc, .vault-token, id_ecdsa, credentials.db, access_tokens.json and stored_tokens)
  • Environment variables that indicate tokens, passwords, API keys, private keys, session cookies and database or message-broker connection strings (e.g., NPM_TOKEN and PYPI_API_TOKEN)
  • AWS access keys, GitHub and GitLab tokens, npm and PyPI tokens, Hugging Face, HashiCorp Vault, Slack, Stripe and SendGrid keys, and JWTs

SafeDep, in its analysis of the supply chain attack, said the attacker obtained the publish tokens from MemTensor’s own GitHub Actions release pipelines by pushing commits that caused the workflow to hand over the npm or PyPI token.

A deeper examination of the implant suggests that it can function like a worm by self-proliferating through GitHub and direct npm and PyPI package publishing. As of writing, it’s unclear if there are packages other than MemTensor that are impacted by the compromise.

“It collects credentials from developer machines and from CI jobs,” SafeDep said. “It receives signed tasks from a command-and-control (C2) server. It also contains templates to install itself in npm packages, Python packages, and GitHub Actions workflows.”

Given that the malicious versions of the npm packages are still available for download, it’s essential to pin the packages to a safe baseline version (0.1.20 for the npm package, 2.0.33 for the PyPI package), rotate exposed secrets,  kill any sckit process, and block “skyleen[.]fr” and all its subdomains.

“The MemOS Cloud plugin connects the OpenClaw agent runtime to a memory service,” StepSecurity said. “Its normal work includes recalling relevant memories before an agent processes a prompt and adding memories after a run. The package also declares integration points for the Clawdbot and Moltbot runtimes.”

“This places the plugin inside a process that routinely handles user input and may inherit valuable credentials. On a developer workstation, the same user account can have access to cloud configuration, source repositories, package publishing tokens, and application secrets. In automation, the process may receive credentials injected for a particular job.”



Source link

The Hacker News

The Hacker News

Next Post

CloudZero launches AI Signals to put finance leaders back in control of AI spend

Recommended.

Mobile Connectivity Expert GlocalMe Showcases All-Around, Always-On Connectivity at IFA 2026

September 5, 2026
China Mobile International Launches SJC2 to Enable Seamless Connectivity Across Asia-Pacific

China Mobile International Launches SJC2 to Enable Seamless Connectivity Across Asia-Pacific

July 18, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio