By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Compromised MemTensor Packages Distribute sckit Stealer

Unknown threat actors have successfully compromised two legitimate MemTensor packages, specifically within the npm and Python Package Index (PyPI) repositories. These compromised packages were used to distribute a platform-specific Go-based implant known as sckit. The sckit implant is designed to operate across multiple operating systems, including Windows, Linux, and macOS, indicating a broad targeting strategy by the attackers. This discovery was reported by a consortium of security firms including Aikido, SafeDep, Socket, and StepSecurity. The specific compromised libraries identified are @memtensor/memos-cloud-openclaw-plugin and @memtensor/memos-cloud-openclaw-plugin, with versions of the packages being affected. The attackers leveraged these trusted distribution channels to inject malicious code, aiming to bypass security measures that might otherwise flag standalone malicious software. The sckit implant's primary function is to steal credentials, a common objective for financially motivated cybercriminals or espionage actors. By embedding the malicious code within seemingly legitimate software components, the threat actors increase the likelihood of the implant being downloaded and executed by unsuspecting developers and users. The use of Go for the implant suggests a focus on cross-platform compatibility and efficient execution. The compromise of packages hosted on npm and PyPI highlights a persistent threat vector in the software supply chain. These repositories are widely used by developers globally, making them attractive targets for attackers seeking to distribute malware at scale. The security firms involved in the detection and reporting of this incident have provided technical details and indicators of compromise to aid in the mitigation and investigation of this threat. The incident underscores the critical importance of robust software supply chain security practices, including thorough vetting of dependencies, continuous monitoring of package integrity, and the implementation of security tools that can detect malicious code within legitimate-looking packages. The MemTensor organization, whose packages were compromised, is likely to face scrutiny regarding its security protocols and the process by which its packages were infiltrated. Further investigation will likely focus on how the threat actors gained access to the package maintainer's accounts or build pipelines, and the specific methods used to inject the sckit implant into the legitimate code. The broad applicability of the sckit implant across major operating systems suggests a sophisticated operation with the potential to impact a significant number of users and organizations that rely on these software packages. The ongoing analysis by security researchers aims to fully understand the capabilities of the sckit implant and the full extent of the compromise.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.