Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Compromised MemTensor packages on npm and PyPI deliver a cross-platform credential stealer, using stolen GitHub Actions tokens for distribution.
A supply chain attack has compromised legitimate MemTensor packages on npm and PyPI to distribute a Go-based credential stealer named 'sckit'. The malicious packages target Windows, Linux, and macOS, stealing credentials from cloud services (AWS, GCP), source code platforms (GitHub, GitLab), package registries, and developer tools. The attacker gained publish tokens by exploiting MemTensor's GitHub Actions pipelines. The implant exfiltrates data to an external server and can self-propagate through GitHub and package publishing.
80