Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.

According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below –

@memtensor/memos-cloud-openclaw-plugin versions

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Open-Source AI and Open Models Reading List

Open-Source AI and Open Models Reading List Source: Hacker News

Devil’s Arrows: Ancient builders hauled 55k-lb stones 11 miles for UK stone row

Devil’s Arrows: Ancient builders hauled 55k-lb stones 11 miles for UK stone row Source: Hacker News

AI can’t be listed as inventor on patent applications, Japan’s top court rules

AI can’t be listed as inventor on patent applications, Japan’s top court rules Source: Hacker News