> Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
[DATE: 23/09/2026 13:52]
[LANGUAGE: EN]
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.
According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below -
@memtensor/memos-cloud-openclaw-plugin versions