Skip to main content
The Wire
CyberNews by Zentrya One
Malware

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Compromised MemTensor packages on npm and PyPI deliver the cross-platform sckit credential stealer, targeting GitHub, AWS, SSH, npm, PyPI and developer secrets.

Cybersecurity researchers have uncovered a software supply-chain attack targeting MemTensor packages on npm and PyPI, where compromised legitimate releases were modified to deliver a cross-platform credential-stealing implant called sckit.

The malicious Go-based payload targets Windows, Linux, and macOS, searching developer environments for cloud credentials, source-code tokens, package-registry secrets, SSH keys, and other sensitive information.

Affected Packages

Researchers identified the following malicious releases:

Ecosystem Package Malicious Versions
npm @memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23, 0.1.25
PyPI MemoryOS 2.0.34

Interestingly, npm versions 0.1.22 and 0.1.24 were clean, despite being released between malicious versions. Researchers recommend using 0.1.20 as the known-good npm baseline and 2.0.33 for the PyPI package while investigating potentially affected systems.

How sckit Executes

The malicious payload does not rely on a traditional installation script.

In the compromised npm plugin, sckit launches when the OpenClaw gateway starts and again during memory-recall operations. During recall, the user's prompt text can also be passed to the malicious executable.

In the PyPI package, the malware is triggered when the memos module loads. This means controls such as npm's --ignore-scripts do not necessarily prevent execution.

The attack can be summarized as:

Compromised MemTensor Package → Developer Installs/Loads Package → sckit Executes → Credentials Collected → Data Exfiltrated → Potential Supply-Chain Propagation

What Credentials Does sckit Target?

The malware searches developer home directories and environment variables for credentials associated with services including:

  • GitHub and GitLab
  • npm and PyPI
  • AWS
  • HashiCorp Vault
  • SSH
  • Hugging Face
  • Slack
  • Stripe
  • SendGrid

It also searches for API keys, passwords, private keys, JWTs, session information, database connection strings, and files such as .npmrc, .vault-token, AWS credential files, and SSH keys.

Collected information is sent to attacker-controlled infrastructure under:

skyleen[.]fr

Worm-Like Supply-Chain Capabilities

Researchers warn that sckit goes beyond conventional credential theft.

Analysis found functionality designed to use stolen GitHub, npm, and PyPI credentials to propagate into additional repositories and software packages. The implant contains templates for inserting itself into npm packages, Python packages, and GitHub Actions workflows.

This creates a potentially dangerous cycle:

Developer Compromise → Credential Theft → Repository/Registry Access → Package Compromise → New Developer Infections

At the time of reporting, researchers had not confirmed that additional packages beyond the identified MemTensor releases had been successfully compromised through this propagation mechanism.

Release Infrastructure Was Targeted

SafeDep's investigation found evidence that the attackers manipulated MemTensor's development and release process, including changes intended to expose npm and PyPI publishing credentials from GitHub Actions workflows.

Malicious commits added the sckit binaries and modified release tooling. Researchers have not conclusively established how the attacker initially obtained access to MemTensor's GitHub environment.

What Developers Should Do

Anyone who installed or executed an affected version should treat credentials accessible from that environment as potentially exposed.

Recommended actions include:

  • Remove the malicious package versions.
  • Pin dependencies to verified clean releases.
  • Terminate any running sckit processes.
  • Block skyleen[.]fr and its subdomains.
  • Rotate npm and PyPI publishing tokens.
  • Revoke GitHub and GitLab tokens.
  • Rotate AWS, Vault, SSH, and other accessible secrets.
  • Review GitHub Actions and CI/CD workflows for unauthorized changes.
  • Audit recently published packages and repository commits.
  • Check developer workstations and CI runners for indicators of compromise.

Simply downgrading the package is not sufficient if sckit already executed, because credentials may already have been collected and exfiltrated.

Security Takeaway

The MemTensor incident demonstrates why developer environments have become high-value supply-chain targets.

By compromising trusted packages, sckit could potentially turn one infected developer or CI pipeline into credentials for accessing additional repositories and package registries.

Trusted Package → Credential Stealer → Developer Secrets → Publishing Access → Potential Supply-Chain Expansion

Organizations using MemTensor should identify exactly which package versions were installed, rotate exposed credentials, and review both developer endpoints and CI/CD infrastructure for signs of compromise.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.