Sckit credential-stealing Go implant in compromised MemTensor packages
Malware Activity
Summary
Hide ▲
Show ▼
The sckit implant is being delivered through compromised MemTensor packages on npm and PyPI, turning routine installs into cross-platform credential theft from developer and CI environments. The malicious npm builds execute when the agent gateway starts or when a memory-recall event fires, while the PyPI package launches a Go binary on module import. The payload harvests secrets from cloud services, source-code platforms, package registries, and developer tools, then exfiltrates them to skyleen[.]fr. The same implant can also self-propagate through GitHub and direct package publishing, widening the blast radius.
Related Happenings
Claude-built malicious Python package on PyPI
Malware Activity
H score14
First: 31.07.2026 03:57
Last: 31.07.2026 03:57
Sources 1
About this happening:
A Claude-built malicious Python package was uploaded to PyPI and executed on 15 real systems, creating a live malware delivery chain before registry defenses removed i...
Claude-built malicious Python package on PyPI
Malware ActivityAbout this happening: A Claude-built malicious Python package was uploaded to PyPI and executed on 15 real systems, creating a live malware delivery chain before registry defenses removed i...
Compromised @asyncapi npm packages distributing the Miasma loader
Malware Activity
H score29
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Compromised @asyncapi npm packages distributing the Miasma loader
Malware ActivityAbout this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Malicious npm and PyPI payment SDK typosquat packages
Malware Activity
H score40
First: 09.07.2026 18:09
Last: 09.07.2026 18:09
Sources 1
About this happening:
The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Malicious npm and PyPI payment SDK typosquat packages
Malware ActivityAbout this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Malicious npm and PyPI Paysafe, Skrill, and Neteller SDK packages delivering stealer malware
Malware Activity
H score37
First: 08.07.2026 22:54
Last: 08.07.2026 22:54
Sources 1
About this happening:
Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs delivered stealer malware that siphoned secrets from developer environment...
Malicious npm and PyPI Paysafe, Skrill, and Neteller SDK packages delivering stealer malware
Malware ActivityAbout this happening: Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs delivered stealer malware that siphoned secrets from developer environment...
Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
H score16
First: 03.07.2026 19:07
Last: 03.07.2026 19:07
Sources 1
About this happening:
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Rollup polyfill npm package malware activity for remote access and data theft
Malware ActivityAbout this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Timeline
-
23.09.2026 16:52 2 articles · 3h ago
Compromised MemTensor npm and PyPI packages deliver sckit credential stealer
Initial DisclosureUnknown threat actors compromised two legitimate MemTensor packages on npm and PyPI to deliver sckit, a Go-based implant designed for Windows, Linux, and macOS. The malicious npm versions 0.1.21, 0.1.23, and 0.1.25 launch the payload when the agent gateway starts or when the plugin handles a memory-recall event, while MemoryOS 2.0.34 starts the Go binary when the memos module is imported. The payload is described as a credential-stealing tool that targets secrets in developer machines, CI jobs, cloud services, source-code platforms, package registries, and developer tools, then exfiltrates data to skyleen[.]fr.
Show sources
- Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI — thehackernews.com — 23.09.2026 16:52
- Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI — thehackernews.com — 23.09.2026 16:52