Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Compromised MemTensor packages on npm and PyPI deliver the cross-platform sckit credential stealer, targeting GitHub, AWS, SSH, npm, PyPI and developer secrets.

Cybersecurity researchers have uncovered a software supply-chain attack targeting MemTensor packages on npm and PyPI, where compromised legitimate releases were modified to deliver a cross-platform credential-stealing implant called sckit.
The malicious Go-based payload targets Windows, Linux, and macOS, searching developer environments for cloud credentials, source-code tokens, package-registry secrets, SSH keys, and other sensitive information.
Affected Packages
Researchers identified the following malicious releases:
| Ecosystem | Package | Malicious Versions |
|---|---|---|
| npm | @memtensor/memos-cloud-openclaw-plugin |
0.1.21, 0.1.23, 0.1.25 |
| PyPI | MemoryOS |
2.0.34 |
Interestingly, npm versions 0.1.22 and 0.1.24 were clean, despite being released between malicious versions. Researchers recommend using 0.1.20 as the known-good npm baseline and 2.0.33 for the PyPI package while investigating potentially affected systems.
How sckit Executes
The malicious payload does not rely on a traditional installation script.
In the compromised npm plugin, sckit launches when the OpenClaw gateway starts and again during memory-recall operations. During recall, the user's prompt text can also be passed to the malicious executable.
In the PyPI package, the malware is triggered when the memos module loads. This means controls such as npm's --ignore-scripts do not necessarily prevent execution.
The attack can be summarized as:
Compromised MemTensor Package → Developer Installs/Loads Package → sckit Executes → Credentials Collected → Data Exfiltrated → Potential Supply-Chain Propagation
What Credentials Does sckit Target?
The malware searches developer home directories and environment variables for credentials associated with services including:
- GitHub and GitLab
- npm and PyPI
- AWS
- HashiCorp Vault
- SSH
- Hugging Face
- Slack
- Stripe
- SendGrid
It also searches for API keys, passwords, private keys, JWTs, session information, database connection strings, and files such as .npmrc, .vault-token, AWS credential files, and SSH keys.
Collected information is sent to attacker-controlled infrastructure under:
skyleen[.]fr
Worm-Like Supply-Chain Capabilities
Researchers warn that sckit goes beyond conventional credential theft.
Analysis found functionality designed to use stolen GitHub, npm, and PyPI credentials to propagate into additional repositories and software packages. The implant contains templates for inserting itself into npm packages, Python packages, and GitHub Actions workflows.
This creates a potentially dangerous cycle:
Developer Compromise → Credential Theft → Repository/Registry Access → Package Compromise → New Developer Infections
At the time of reporting, researchers had not confirmed that additional packages beyond the identified MemTensor releases had been successfully compromised through this propagation mechanism.
Release Infrastructure Was Targeted
SafeDep's investigation found evidence that the attackers manipulated MemTensor's development and release process, including changes intended to expose npm and PyPI publishing credentials from GitHub Actions workflows.
Malicious commits added the sckit binaries and modified release tooling. Researchers have not conclusively established how the attacker initially obtained access to MemTensor's GitHub environment.
What Developers Should Do
Anyone who installed or executed an affected version should treat credentials accessible from that environment as potentially exposed.
Recommended actions include:
- Remove the malicious package versions.
- Pin dependencies to verified clean releases.
- Terminate any running
sckitprocesses. - Block
skyleen[.]frand its subdomains. - Rotate npm and PyPI publishing tokens.
- Revoke GitHub and GitLab tokens.
- Rotate AWS, Vault, SSH, and other accessible secrets.
- Review GitHub Actions and CI/CD workflows for unauthorized changes.
- Audit recently published packages and repository commits.
- Check developer workstations and CI runners for indicators of compromise.
Simply downgrading the package is not sufficient if sckit already executed, because credentials may already have been collected and exfiltrated.
Security Takeaway
The MemTensor incident demonstrates why developer environments have become high-value supply-chain targets.
By compromising trusted packages, sckit could potentially turn one infected developer or CI pipeline into credentials for accessing additional repositories and package registries.
Trusted Package → Credential Stealer → Developer Secrets → Publishing Access → Potential Supply-Chain Expansion
Organizations using MemTensor should identify exactly which package versions were installed, rotate exposed credentials, and review both developer endpoints and CI/CD infrastructure for signs of compromise.
Related reporting
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix
Attackers abuse ChatGPT Custom GPTs and sponsored Google results to redirect victims to ClickFix pages that execute PowerShell and install remote access trojan malware.
Star Blizzard Targets 100+ Organizations With Fake Event Invites and CosmicPulse Backdoor
Russia-linked Star Blizzard targets more than 100 organizations using fake event invitations, the new RedFlick malware delivery technique and the CosmicPulse Windows backdoor.
101 Malicious npm Packages Secretly Add Developers to WhatsApp Groups
Researchers uncover 101 malicious npm packages in the PhantomSub campaign that abuse authenticated WhatsApp sessions to secretly add developers to attacker-controlled groups and channels.


