EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 85/100

Due pacchetti MemTensor su npm e PyPI sono stati compromessi per distribuire sckit, un implant Go-based per rubare credenziali. Le versioni interessate sono 0.1.21, 0.1.23, 0.1.25 (npm) e 2.0.34 (PyPI). L'attacco mira a sfruttare la catena di fornitura per accedere a credenziali e dati sensibili.

Why it matters

Per le PMI italiane, il rischio è elevato: la compromissione di pacchetti di terze parti può portare a furti di credenziali e accesso a dati sensibili. L'attacco potrebbe compromettere sistemi interni e repository di codice, causando perdite significative.

Potential operational benefits

  • Riduzione della superficie esposta attraverso patch e aggiornamenti
  • Prevenzione di accessi non autorizzati grazie a MFA e segmentazione
  • Rilevamento tempestivo di attività sospette grazie al monitoraggio SIEM
  • Protezione dei dati sensibili grazie a backup e DR
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementSegmentazione di reteMonitoraggio / SIEMMFA / IdentitàBackup & DR
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
23/09/2026 15:52
MITRE ATT&CK
T1190, T1486, T1059.001
Open the original source