Back to all news
Security

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News·September 23, 2026·1 min read
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors compromised two legitimate MemTensor packages on npm and PyPI to deliver a Go-based implant called sckit targeting Windows, Linux, and macOS. The malicious libraries, including @memtensor/memos-cloud-openclaw-plugin, were flagged by Aikido, SafeDep, Socket, and StepSecurity. Users who installed the packages may have had credentials stolen.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store