{"id":3101,"date":"2026-09-23T14:31:38","date_gmt":"2026-09-23T14:31:38","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3101"},"modified":"2026-09-23T14:31:38","modified_gmt":"2026-09-23T14:31:38","slug":"compromised-memtensor-packages-deliver-sckit-credential-stealer-via-npm-and-pypi","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3101","title":{"rendered":"Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 23, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Cloud Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFThFSFsti-2SIka75bNuMKpyJHtOW2ZPrZtcSjbjFQ64GCNn0WtdssYuWlVTbhaLB5cAJ0vu8FgyNmNsDa8g0Ijy-D1zP4FW7ihVfAjk9xWMYDMMdfZPICGyVdjeDwH3-jyKLHOUnjfaXBJIMxGn_3ngeXFsbb4CLnOibRd4fbwXHYpBkMQTcBQAf0edq\/s1700-nu-rw-lo-l85-e365\/npm-pypi.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed <strong>sckit<\/strong> designed for Windows, Linux, and macOS.<\/p>\n<p>According to reports from <a href=\"https:\/\/www.aikido.dev\/blog\/supplychain-local-memtensor-npm-pypi\" target=\"_blank\">Aikido<\/a>, <a href=\"https:\/\/safedep.io\/memtensor-sckit-worm-npm-pypi\/\" target=\"_blank\">SafeDep<\/a>, <a href=\"https:\/\/socket.dev\/blog\/memtensor-compromise\" target=\"_blank\">Socket<\/a>, and <a href=\"https:\/\/www.stepsecurity.io\/blog\/sckit-supply-chain-worm-hits-memtensor-npm-pypi-scopes\" target=\"_blank\">StepSecurity<\/a>, the libraries in question below &#8211;<\/p>\n<p>The malicious npm package versions include a \u00abhidden Go payload into a legitimate AI memory integration. Versions 0.1.21, 0.1.23, and 0.1.25 contain code that launches the payload when the agent gateway starts and whenever the plugin handles a memory-recall event,\u00bb StepSecurity said.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe launcher passes the host process environment and, during recall, the user&#8217;s prompt text directly to the malicious executable.\u00bb<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The PyPI package, on the other hand, starts the statically-linked Go binary as soon as the \u00abmemos\u00bb module is imported into an application.<\/p>\n<p>Regardless of the ecosystem targeted, the end goal is to launch a cross-platform credential-stealing payload capable of harvesting sensitive data from cloud services, source-code platforms, package registries, and developer tools and exfiltrating the details to an external server (\u00abskyleen[.]fr\u00bb).<\/p>\n<p>According to Socket, targets include npm, PyPI, GitHub, GitLab, AWS, Vault and SSH secrets &#8211;<\/p>\n<ul>\n<li>Credential files (.npmrc, .vault-token, id_ecdsa, credentials.db, access_tokens.json and stored_tokens)<\/li>\n<li>Environment variables that indicate tokens, passwords, API keys, private keys, session cookies and database or message-broker connection strings (e.g., NPM_TOKEN and PYPI_API_TOKEN)<\/li>\n<li>AWS access keys, GitHub and GitLab tokens, npm and PyPI tokens, Hugging Face, HashiCorp Vault, Slack, Stripe and SendGrid keys, and JWTs<\/li>\n<\/ul>\n<p>SafeDep, in its analysis of the supply chain attack, said the attacker obtained the publish tokens from MemTensor&#8217;s own GitHub Actions release pipelines by pushing commits that caused the workflow to hand over the npm or PyPI token.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEih9Eq3x05ST2UXweOaS-XCZ1cdO7H_JA7mKniiQTEp3M1QHZBFvppYcCVWEe-GzOc6NzP9ApIc7Kn6adsYciQ3J3Okl185Ji1enErQai6l2G2XZ5AXUWkyU5b523LXogsByGTl-1iw6l_UFXFCYTOiIxtEcPIvGuPmGjVqUnU1fOanLLYbnbzHnnzBuPcN\/s1700-nu-rw-lo-l85-e365\/sckit.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEih9Eq3x05ST2UXweOaS-XCZ1cdO7H_JA7mKniiQTEp3M1QHZBFvppYcCVWEe-GzOc6NzP9ApIc7Kn6adsYciQ3J3Okl185Ji1enErQai6l2G2XZ5AXUWkyU5b523LXogsByGTl-1iw6l_UFXFCYTOiIxtEcPIvGuPmGjVqUnU1fOanLLYbnbzHnnzBuPcN\/s1700-nu-rw-lo-l85-e365\/sckit.jpg\" alt=\"\" border=\"0\" data-original-height=\"840\" data-original-width=\"1280\"\/><\/a><\/div>\n<p>A deeper examination of the implant suggests that it can function like a worm by self-proliferating through GitHub and direct npm and PyPI package publishing. As of writing, it&#8217;s unclear if there are packages other than MemTensor that are impacted by the compromise.<\/p>\n<p>\u00abIt collects credentials from developer machines and from CI jobs,\u00bb SafeDep <a href=\"https:\/\/safedep.io\/sckit-go-implant-framework\/\" target=\"_blank\">said<\/a>. \u00abIt receives signed tasks from a command-and-control (C2) server. It also contains templates to install itself in npm packages, Python packages, and GitHub Actions workflows.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Given that the malicious versions of the npm packages are still available for download, it&#8217;s essential to pin the packages to a safe baseline version (0.1.20 for the npm package, 2.0.33 for the PyPI package), rotate exposed secrets,  kill any sckit process, and block \u00abskyleen[.]fr\u00bb and all its subdomains.<\/p>\n<p>\u00abThe MemOS Cloud plugin connects the OpenClaw agent runtime to a memory service,\u00bb StepSecurity said. \u00abIts normal work includes recalling relevant memories before an agent processes a prompt and adding memories after a run. The package also declares integration points for the Clawdbot and Moltbot runtimes.\u00bb<\/p>\n<p>\u00abThis places the plugin inside a process that routinely handles user input and may inherit valuable credentials. On a developer workstation, the same user account can have access to cloud configuration, source repositories, package publishing tokens, and application secrets. In automation, the process may receive credentials injected for a particular job.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 23, 2026Malware \/ Cloud Security Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3102,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[227,459,529,3515,39,35,934,3516,478],"class_list":["post-3101","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-compromised","tag-credential","tag-deliver","tag-memtensor","tag-npm","tag-packages","tag-pypi","tag-sckit","tag-stealer"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3101","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3101"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3101\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3102"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3101"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3101"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3101"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}