CyberSecurity News
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
AI summary
Unknown threat actors have compromised two legitimate MemTensor packages on npm and PyPI, using them to distribute a Go-based implant called sckit. The sckit implant is designed to work on multiple platforms, including Windows, Linux, and macOS. The compromise was reported by several security companies, including Aikido, SafeDep, Socket, and StepSecurity. The affected packages include a specific version of the @memtensor/memos-cloud-openclaw-plugin. The sckit implant is a credential stealer.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

