Unknown threat actors have successfully compromised legitimate MemTensor packages across both npm and PyPI, injecting a multi-platform credential stealer called sckit into the software supply chain. Security firms Aikido, SafeDep, Socket, and StepSecurity identified the attack, which affected @memtensor/memos-cloud-openclaw-plugin on npm and corresponding packages on PyPI.
Sckit operates as a Go-based implant targeting Windows, Linux, and macOS systems. The malware functions as a credential harvester, capable of stealing authentication data from compromised machines. The attack leveraged the trust that developers place in established package repositories, making sckit particularly dangerous because it distributed through legitimate package channels developers rely on daily.
The compromise of MemTensor packages represents a classic supply chain attack vector. Threat actors gained control of the legitimate package maintenance credentials or repository access, then pushed malicious versions containing sckit to unsuspecting developers. Anyone who installed the compromised versions pulled the malware directly into their development environments and production systems. This approach bypasses traditional security controls because the packages came from trusted sources.
The multi-platform nature of sckit distinguishes this threat. Rather than targeting a single operating system, the malware supports Windows, Linux, and macOS. This breadth indicates attackers designed sckit for widespread deployment across heterogeneous infrastructure. Organizations running mixed environments faced uniform risk exposure. Developers using the compromised packages on any supported platform became victims simultaneously.
Package repositories like npm and PyPI serve as central distribution hubs for millions of developers worldwide. Compromises at this level create cascading risk across dependent projects. When attackers poison upstream packages, they contaminate everything downstream. A single compromised library can spread malware across thousands of applications, organizations, and end-user systems. The attack surface expands exponentially through transitive dependencies.
Credential theft through sckit poses direct risks to affected organizations. Stolen credentials enable attackers to access internal systems, cloud environments, version control repositories, and sensitive applications. An attacker with legitimate credentials moves through networks undetected, appearing as trusted users. They can exfiltrate data, establish persistence, deploy additional malware, or launch lateral movement campaigns.
The incident demonstrates that package repository security remains contested territory. While npm and PyPI implement verification systems, determined attackers can still compromise developer accounts or exploit process weaknesses. Organizations cannot assume package repository integrity. They must implement additional controls.
Developers using MemTensor packages should immediately audit their systems for sckit artifacts. This includes checking process execution logs, network connections, and credential access patterns. Rotating credentials accessed from compromised machines becomes essential. Developers should upgrade to patched versions once repositories remove malicious packages.
Broader defensive practices mitigate supply chain risk. Dependency scanning tools can detect known malicious packages before installation. Sandboxed build environments limit malware spread if compromised packages execute during builds. Software composition analysis identifies when projects depend on high-risk packages. Organizations should implement least-privilege access controls so stolen credentials grant minimal damage.
This incident reinforces that trust in software dependencies requires continuous verification, not passive acceptance. The open-source ecosystem's distributed nature creates both innovation and risk. Security teams must treat package repositories as potential attack vectors requiring active monitoring and validation.
