AI Weekly Malaysia

Back to items Summaries

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

ID
27764
Status
summarized
Published
23 Sep 2026, 9:52 PM
Fetched
24 Sep 2026, 12:05 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
24 Sep 2026, 12:10 AM
Tags
Audience
developersai_agent_userssaas_founders

What happened

Attackers compromised two legitimate MemTensor packages—@memtensor/memos-cloud-openclaw-plugin (npm, versions 0.1.21, 0.1.23, 0.1.25) and MemoryOS (PyPI, version 2.0.34)—to deliver a cross-platform Go-based credential stealer called sckit. The malware harvests tokens and secrets from AWS, GitHub, GitLab, npm, PyPI, Hugging Face, Vault, Slack, Stripe, SendGrid, and SSH, exfiltrating them to skyleen[.]fr. Attackers obtained publish tokens by exploiting MemTensor's GitHub Actions release pipelines.

Why it matters

If you use @memtensor/memos-cloud-openclaw-plugin or MemoryOS in your AI agent or memory stack, pin to the clean versions (0.1.22 or 0.1.24 for npm) or remove the dependency entirely, then rotate any exposed credentials—especially NPM_TOKEN, PYPI_API_TOKEN, AWS keys, and GitHub/GitLab tokens. This also illustrates why your own CI/CD release pipelines should never expose publish tokens to arbitrary commits without branch protection or secret gating.

Discussion angle

How many of us audit the GitHub Actions workflows that hold our npm/PyPI publish tokens—and what's the minimum viable hardening (branch protection, OIDC federation, least-privilege tokens) to prevent this exact vector?

Top