hacker-news · Crawled Sep 23, 2026
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
5 IoCs
Read original article ↗
AI Summary
Unknown threat actors have compromised specific versions of the MemTensor packages on npm and PyPI, injecting a malicious Go-based credential stealer named sckit. The malicious packages, when used in development or CI environments, execute a payload that harvests sensitive credentials from cloud services, source control, package registries, and developer tools. The malware exfiltrates stolen data to the domain skyleen[.]fr and can self-propagate via GitHub, npm, and PyPI. Organizations are advised to pin to known clean versions, rotate secrets, and block the C2 domain.
AI-extracted · verify before operational use
Indicators of Compromise 5 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | skyleen[.]fr | Details → |
| Package | @memtensor/[email protected] | Details → |
| Package | @memtensor/[email protected] | Details → |
| Package | @memtensor/[email protected] | Details → |
| Package | [email protected] | Details → |