Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Summary

Unknown threat actors have compromised two legitimate MemTensor packages on npm and PyPI, injecting a Go-based implant called sckit. This implant is designed to steal credentials and operates on Windows, Linux, and macOS systems.

IFF Assessment

FOE

The compromise of software packages with a credential stealer represents a direct threat to the security of users and systems, negatively impacting defenders.

Defender Context

This incident highlights the ongoing risk of supply chain attacks, where legitimate software repositories are leveraged to distribute malicious code. Defenders need to be vigilant about verifying the integrity of packages they download and use, implementing robust dependency scanning, and maintaining awareness of known compromised libraries.

Read Full Story →