Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
- ID
- 27764
- Status
- summarized
- Published
- 23 Sep 2026, 9:52 PM
- Fetched
- 24 Sep 2026, 12:05 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 24 Sep 2026, 12:10 AM
- Tags
- Audience
- developersai_agent_userssaas_founders
What happened
Attackers compromised two legitimate MemTensor packages—@memtensor/memos-cloud-openclaw-plugin (npm, versions 0.1.21, 0.1.23, 0.1.25) and MemoryOS (PyPI, version 2.0.34)—to deliver a cross-platform Go-based credential stealer called sckit. The malware harvests tokens and secrets from AWS, GitHub, GitLab, npm, PyPI, Hugging Face, Vault, Slack, Stripe, SendGrid, and SSH, exfiltrating them to skyleen[.]fr. Attackers obtained publish tokens by exploiting MemTensor's GitHub Actions release pipelines.
Why it matters
If you use @memtensor/memos-cloud-openclaw-plugin or MemoryOS in your AI agent or memory stack, pin to the clean versions (0.1.22 or 0.1.24 for npm) or remove the dependency entirely, then rotate any exposed credentials—especially NPM_TOKEN, PYPI_API_TOKEN, AWS keys, and GitHub/GitLab tokens. This also illustrates why your own CI/CD release pipelines should never expose publish tokens to arbitrary commits without branch protection or secret gating.
Discussion angle
How many of us audit the GitHub Actions workflows that hold our npm/PyPI publish tokens—and what's the minimum viable hardening (branch protection, OIDC federation, least-privilege tokens) to prevent this exact vector?