Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
A recent threat incident has exposed users to potential security risks as unknown actors managed to compromise two legitimate MemTensor packages on the npm and PyPI repositories. These compromised packages were used to distribute a platform-specific sckit implant, which targets Windows, Linux, and macOS systems.
According to reports from Aikido, SafeDep, Socket, and StepSecurity, the compromised libraries are identified as:
- @memtensor/memos-cloud-openclaw-plugin versions
The sckit implant is a credential stealer designed to exploit vulnerabilities in affected systems. It is believed that the threat actors behind this attack have successfully infiltrated the npm and PyPI repositories, allowing them to bypass security checks and distribute malicious software to unsuspecting users.
This incident highlights the importance of staying vigilant when installing packages from untrusted sources and regularly updating software to protect against such threats. Users are advised to review the packages they install and ensure they come from trusted sources to minimize the risk of compromise.
SpeakOX News will continue to monitor the situation and provide updates as more information becomes available.
<small>Source: The Hacker News — read the original story there.</small>