Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Subsea Cable Assets wins first contract with Saipem, worth $20 million

    September 23, 2026

    Britain’s far-right violence comes to us direct from the 1970s. But so does the solution | Taj Ali

    September 23, 2026

    Don’t go bananas over tale of chimp rescuing zookeeper

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Subsea Cable Assets wins first contract with Saipem, worth $20 million
    • Britain’s far-right violence comes to us direct from the 1970s. But so does the solution | Taj Ali
    • Don’t go bananas over tale of chimp rescuing zookeeper
    • Ethiopia and Tigray accuse each of launching offensives, fuelling fears of new war
    • UK to join EU ocean science scheme to better predict extreme weather events | Climate crisis
    • Nearly 70% of workers use AI regularly now – but many get no time to upskill
    • Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
    • Raiffeisen Expands Crypto Access With Bitpanda
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 23, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 23, 2026Malware / Cloud Security

    Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.

    According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below –

    The malicious npm package versions include a “hidden Go payload into a legitimate AI memory integration. Versions 0.1.21, 0.1.23, and 0.1.25 contain code that launches the payload when the agent gateway starts and whenever the plugin handles a memory-recall event,” StepSecurity said.

    Cybersecurity

    “The launcher passes the host process environment and, during recall, the user’s prompt text directly to the malicious executable.”

    The PyPI package, on the other hand, starts the statically-linked Go binary as soon as the “memos” module is imported into an application.

    Regardless of the ecosystem targeted, the end goal is to launch a cross-platform credential-stealing payload capable of harvesting sensitive data from cloud services, source-code platforms, package registries, and developer tools and exfiltrating the details to an external server (“skyleen[.]fr”).

    According to Socket, targets include npm, PyPI, GitHub, GitLab, AWS, Vault and SSH secrets –

    • Credential files (.npmrc, .vault-token, id_ecdsa, credentials.db, access_tokens.json and stored_tokens)
    • Environment variables that indicate tokens, passwords, API keys, private keys, session cookies and database or message-broker connection strings (e.g., NPM_TOKEN and PYPI_API_TOKEN)
    • AWS access keys, GitHub and GitLab tokens, npm and PyPI tokens, Hugging Face, HashiCorp Vault, Slack, Stripe and SendGrid keys, and JWTs

    SafeDep, in its analysis of the supply chain attack, said the attacker obtained the publish tokens from MemTensor’s own GitHub Actions release pipelines by pushing commits that caused the workflow to hand over the npm or PyPI token.

    A deeper examination of the implant suggests that it can function like a worm by self-proliferating through GitHub and direct npm and PyPI package publishing. As of writing, it’s unclear if there are packages other than MemTensor that are impacted by the compromise.

    “It collects credentials from developer machines and from CI jobs,” SafeDep said. “It receives signed tasks from a command-and-control (C2) server. It also contains templates to install itself in npm packages, Python packages, and GitHub Actions workflows.”

    Cybersecurity

    Given that the malicious versions of the npm packages are still available for download, it’s essential to pin the packages to a safe baseline version (0.1.20 for the npm package, 2.0.33 for the PyPI package), rotate exposed secrets, kill any sckit process, and block “skyleen[.]fr” and all its subdomains.

    “The MemOS Cloud plugin connects the OpenClaw agent runtime to a memory service,” StepSecurity said. “Its normal work includes recalling relevant memories before an agent processes a prompt and adding memories after a run. The package also declares integration points for the Clawdbot and Moltbot runtimes.”

    “This places the plugin inside a process that routinely handles user input and may inherit valuable credentials. On a developer workstation, the same user account can have access to cloud configuration, source repositories, package publishing tokens, and application secrets. In automation, the process may receive credentials injected for a particular job.”

    Compromised Credential deliver MemTensor npm Packages PyPI sckit Stealer
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Arista patches actively exploited VeloCloud Orchestrator zero-day

    Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

    Microsoft: September Windows updates break Always On VPN connections

    D-Link warns of max severity zero-day bug in DIR-822A routers

    F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

    Ryuk ransomware member sentenced to 24 months in prison

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Subsea Cable Assets wins first contract with Saipem, worth $20 million

    September 23, 2026

    Britain’s far-right violence comes to us direct from the 1970s. But so does the solution | Taj Ali

    September 23, 2026

    Don’t go bananas over tale of chimp rescuing zookeeper

    September 23, 2026

    Ethiopia and Tigray accuse each of launching offensives, fuelling fears of new war

    September 23, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subsea Cable Assets wins first contract with Saipem, worth $20 million

    September 23, 2026

    Britain’s far-right violence comes to us direct from the 1970s. But so does the solution | Taj Ali

    September 23, 2026

    Don’t go bananas over tale of chimp rescuing zookeeper

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.