Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Security

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News · Sep 23, 2026

Back to News
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Security September 23, 2026

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.