Find notable cyber news and cases, enriched with sources, timelines, and signals.

Sckit credential-stealing Go implant in compromised MemTensor packages

Malware Activity
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

The sckit implant is being delivered through compromised MemTensor packages on npm and PyPI, turning routine installs into cross-platform credential theft from developer and CI environments. The malicious npm builds execute when the agent gateway starts or when a memory-recall event fires, while the PyPI package launches a Go binary on module import. The payload harvests secrets from cloud services, source-code platforms, package registries, and developer tools, then exfiltrates them to skyleen[.]fr. The same implant can also self-propagate through GitHub and direct package publishing, widening the blast radius.

Related Happenings

Claude-built malicious Python package on PyPI

Malware Activity
H score14 First: 31.07.2026 03:57 Last: 31.07.2026 03:57 Sources 1

About this happening: A Claude-built malicious Python package was uploaded to PyPI and executed on 15 real systems, creating a live malware delivery chain before registry defenses removed i...

Compromised @asyncapi npm packages distributing the Miasma loader

Malware Activity
H score29 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....

Malicious npm and PyPI payment SDK typosquat packages

Malware Activity
H score40 First: 09.07.2026 18:09 Last: 09.07.2026 18:09 Sources 1

About this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...

Malicious npm and PyPI Paysafe, Skrill, and Neteller SDK packages delivering stealer malware

Malware Activity
H score37 First: 08.07.2026 22:54 Last: 08.07.2026 22:54 Sources 1

About this happening: Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs delivered stealer malware that siphoned secrets from developer environment...

Rollup polyfill npm package malware activity for remote access and data theft

Malware Activity
H score16 First: 03.07.2026 19:07 Last: 03.07.2026 19:07 Sources 1

About this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...

Timeline

  1. 23.09.2026 16:52 2 articles · 3h ago

    Compromised MemTensor npm and PyPI packages deliver sckit credential stealer

    Initial Disclosure

    Unknown threat actors compromised two legitimate MemTensor packages on npm and PyPI to deliver sckit, a Go-based implant designed for Windows, Linux, and macOS. The malicious npm versions 0.1.21, 0.1.23, and 0.1.25 launch the payload when the agent gateway starts or when the plugin handles a memory-recall event, while MemoryOS 2.0.34 starts the Go binary when the memos module is imported. The payload is described as a credential-stealing tool that targets secrets in developer machines, CI jobs, cloud services, source-code platforms, package registries, and developer tools, then exfiltrates data to skyleen[.]fr.

    Show sources