Security
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
The Hacker News·September 23, 2026·1 min read
Unknown threat actors compromised two legitimate MemTensor packages on npm and PyPI to deliver a Go-based implant called sckit targeting Windows, Linux, and macOS. The malicious libraries, including @memtensor/memos-cloud-openclaw-plugin, were flagged by Aikido, SafeDep, Socket, and StepSecurity. Users who installed the packages may have had credentials stolen.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
