Compromised MemTensor packages push sckit credential stealer via npm and PyPI
Unknown attackers compromised two legitimate MemTensor packages on npm and PyPI to distribute a Go-based implant called sckit targeting Windows, Linux, and macOS. The threat was flagged by Aikido, SafeDep, Socket, and StepSecurity.
- Two legitimate MemTensor packages compromised on npm and PyPI
- sckit is a Go-based implant for Windows, Linux, and macOS
- Threat flagged by Aikido, SafeDep, Socket, and StepSecurity
- Attack aims to steal developer credentials
Read next
Security