Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
AI-summarised brief · reviewed before publication
Unknown threat actors compromised two legitimate MemTensor packages on npm and PyPI, injecting a Go‑based implant called sckit that targets Windows, Linux, and macOS. Malicious npm versions 0.1.21, 0.1.23, and 0.1.25 launch the payload during agent gateway startup and memory‑recall events, while the PyPI package starts the binary upon import. The implant harvests credentials from cloud services, source‑code platforms, and CI environments, exfiltrating data to an external server (skyleen.fr). Attackers gained publish tokens via MemTensor’s GitHub Actions pipelines, enabling self‑propagation across package ecosystems. Security teams are urged to pin to safe baseline versions, rotate secrets, and block the C2 domain.
💡 Why It Matters
- · The breach demonstrates how compromised package repositories can weaponize AI‑integrated tools, turning routine developer dependencies into covert credential‑stealing vectors.
- · It underscores the urgent need for stricter supply‑chain safeguards and real‑time monitoring of third‑party libraries.