Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.

According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below –

@memtensor/memos-cloud-openclaw-plugin versions

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial

PR spam today looks like email spam in the early 2000s

PR spam today looks like email spam in the early 2000s Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 12.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 171 requests (recent log) 216.73.216.75 — 77 requests (recent log) 216.244.66.232 — 47 requests (recent