πŸ” Search
Sign in to post
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPIhttps://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions

0trust.social media

Loading your media...

Pick a GIF β€” Giphy

Loading GIFs...