hacker-news · Crawled Sep 23, 2026

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

5 IoCs
Read original article ↗

AI Summary

Unknown threat actors have compromised specific versions of the MemTensor packages on npm and PyPI, injecting a malicious Go-based credential stealer named sckit. The malicious packages, when used in development or CI environments, execute a payload that harvests sensitive credentials from cloud services, source control, package registries, and developer tools. The malware exfiltrates stolen data to the domain skyleen[.]fr and can self-propagate via GitHub, npm, and PyPI. Organizations are advised to pin to known clean versions, rotate secrets, and block the C2 domain.

AI-extracted · verify before operational use

Indicators of Compromise 5 extracted

Type Value Detail
Domain skyleen[.]fr Details →
Package @memtensor/[email protected] Details →
Package @memtensor/[email protected] Details →
Package @memtensor/[email protected] Details →
Package [email protected] Details →