- Compromised MemTensor packages on npm and PyPI delivered the Go-based sckit implant across Windows, Linux, and macOS.
- Attackers stole publish tokens from MemTensor’s GitHub Actions pipelines and injected malicious versions into both registries.
- The worm-like implant harvests cloud, source-code, registry, and developer credentials, exfiltrating them to skyleen[.]fr.
On Sep 23, 2026, security researchers reported that unknown threat actors compromised two legitimate MemTensor packages on npm and Python Package Index (PyPI) to distribute a Go-based implant named sckit across Windows, Linux, and macOS. The findings come from Aikido, SafeDep, Socket, and StepSecurity.
StepSecurity said malicious npm versions 0.1.21, 0.1.23, and 0.1.25 contain a “hidden Go payload”; the code launches it when the agent gateway starts and whenever the plugin handles a memory-recall event. “The launcher passes the host process environment and, during recall, the user’s prompt text directly to the malicious executable.”
Meanwhile, the PyPI package starts the statically-linked Go binary as soon as the memos module is imported. The implant is a credential-stealing payload that harvests sensitive data from cloud services, source-code platforms, package registries, and developer tools, exfiltrating details to skyleen[.]fr.
According to Socket, targets include npm, PyPI, GitHub, GitLab, AWS, Vault, and SSH secrets, along with credential files, environment variables, API keys, tokens, and connection strings. SafeDep’s analysis traced the breach to publish tokens stolen from MemTensor’s own GitHub Actions release pipelines after the attacker pushed commits that caused workflows to expose npm or PyPI tokens.
SafeDep described sckit as a worm that self-proliferates through GitHub and direct npm and PyPI package publishing, saying, “It collects credentials from developer machines and from CI jobs.” The implant also receives signed tasks from a command-and-control server and contains templates to install itself in npm packages, Python packages, and GitHub Actions workflows; as of writing, it is unclear whether other packages are affected.
Consequently, with malicious versions still available for download, administrators should pin the npm package to version 0.1.20 and the PyPI package to version 2.0.33, rotate exposed secrets, kill any sckit process, and block skyleen[.]fr and all subdomains. The plugin is part of MemOS Cloud, which connects the OpenClaw agent runtime to a memory service; StepSecurity noted it sits inside a process that handles user input and may inherit valuable credentials.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
