Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.

According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below –

@memtensor/memos-cloud-openclaw-plugin versions

from The Hacker News https://ift.tt/wZtzbS7
https://ift.tt/rOBcM1Q

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these