chiprook
← Security
SecuritySeptember 23, 2026, 20:52

Compromised MemTensor packages push sckit credential stealer via npm and PyPI

Unknown attackers compromised two legitimate MemTensor packages on npm and PyPI to distribute a Go-based implant called sckit targeting Windows, Linux, and macOS. The threat was flagged by Aikido, SafeDep, Socket, and StepSecurity.

Compromised MemTensor packages push sckit credential stealer via npm and PyPI
#MemTensor#Npm#PyPI
Read next
Security

UAE and Saudi Arabia Absorb Half of Gulf Cyberattacks

Security

Hundreds of Leaked GitHub App Keys Still Authenticate

Security

FomoPeek crypto app in App Store hid iOS kernel exploits to steal wallet keys

Security

Attackers Poison ChatGPT, Gemini and Google AI Overview Answers