Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
MemTensor Packages Breached to Deploy Credential Stealer

MemTensor Packages Breached to Deploy Credential Stealer

Posted on September 23, 2026 By CWS

Unknown cybercriminals have successfully infiltrated two legitimate MemTensor packages within the npm and Python Package Index (PyPI) repositories. This breach leverages a specific Go-based malware named ‘sckit’, which is designed to operate across Windows, Linux, and macOS environments.

Details of the Compromised Packages

Reports from security firms such as Aikido, SafeDep, Socket, and StepSecurity highlight that the npm package versions 0.1.21, 0.1.23, and 0.1.25 are affected. These versions integrate a concealed Go payload into an AI memory module, activating the malicious code during memory recall events or when gateway agents initialize.

In the PyPI ecosystem, the threat emerges when the ‘memos’ module is used in an application, triggering the associated Go binary. The ultimate aim of these attacks is to deploy a cross-platform credential-stealing payload, targeting sensitive data from cloud services, source-code platforms, and developer tools, subsequently transmitting this data to an external server.

Targets and Impact

Socket’s analysis indicates that potential targets include npm, PyPI, GitHub, GitLab, AWS, and various credential files and environment variables containing sensitive information like tokens and API keys. The malware is capable of extracting AWS keys, GitHub and GitLab tokens, and other significant credentials.

SafeDep’s investigation into the supply chain attack reveals that the attackers exploited MemTensor’s GitHub Actions release pipelines to obtain publish tokens, facilitating unauthorized npm or PyPI token access. This breach allows the malware to proliferate like a worm across GitHub and other package repositories.

Security Recommendations and Outlook

It is crucial for developers and organizations using these packages to enforce immediate security measures. This includes reverting to baseline package versions—0.1.20 for npm and 2.0.33 for PyPI—rotating exposed secrets, terminating any ‘sckit’ processes, and blocking the ‘skyleen[.]fr’ domain.

As the MemOS Cloud plugin connects to various runtime environments to process and store memory data, it inadvertently becomes a vehicle for credential theft. This is particularly concerning on developer machines and in automated environments where sensitive credentials are routinely handled.

The situation underscores the need for vigilant supply chain security practices and highlights the ongoing risks posed by sophisticated cyber threats targeting software development ecosystems.

The Hacker News Tags:cloud security, credential stealer, Cybersecurity, developer security, Go-based malware, Malware, MemTensor, NPM, PyPI, supply chain attack

Post navigation

Previous Post: NVIDIA Patches Critical Linux Vulnerabilities
Next Post: Exploring AI Threats: Potential Doomsday Scenarios

Related Posts

Browser Extension Risks AI Assistant Security Browser Extension Risks AI Assistant Security The Hacker News
Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware The Hacker News
Critical MOVEit Automation Flaw Patches Released by Progress Critical MOVEit Automation Flaw Patches Released by Progress The Hacker News
Phishing Threats Evolve to Real-Time Insurance Account Hijacking Phishing Threats Evolve to Real-Time Insurance Account Hijacking The Hacker News
Dohdoor Backdoor Threatens U.S. Education & Healthcare Dohdoor Backdoor Threatens U.S. Education & Healthcare The Hacker News
AI Coding Tools Trigger Security Alerts in Endpoint Systems AI Coding Tools Trigger Security Alerts in Endpoint Systems The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical cPanel Security Flaws Threaten User Data
  • Outerlimit Secures $16M to Curb AI Agent Risks
  • AI-Driven Windows Malware Uses Voting System
  • Critical Vulnerability in Next.js Allows RCE via SVG
  • Exploring AI Threats: Potential Doomsday Scenarios

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical cPanel Security Flaws Threaten User Data
  • Outerlimit Secures $16M to Curb AI Agent Risks
  • AI-Driven Windows Malware Uses Voting System
  • Critical Vulnerability in Next.js Allows RCE via SVG
  • Exploring AI Threats: Potential Doomsday Scenarios

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark