πŸ€– Supply chain: two legitimate MemTensor packages on npm and PyPI were compromised to push "sckit", a Go-based credential stealer targeting Windows, Linux, and macOS. Reported by Aikido, SafeDep, Soc

πŸ€– Supply chain: two legitimate MemTensor packages on npm and PyPI were compromised to push "sckit", a Go-based credential stealer targeting Windows, Linux, and macOS. Reported by Aikido, SafeDep, Socket, StepSecurity.

2 reportsother

Claim audit

No BS check run yet β€” press βš– to extract this story's claims and verify them against independent sources.

All coverage

πŸ€– Supply chain: two legitimate MemTensor packages on npm and PyPI were compromised to push "sckit", a Go-based credential stealer targeting Windows, Linux, and macOS. Reported by Aikido, SafeDep, Soc

mastodon:infosec-exchangeother5d ago kagi β†—

πŸ€– Supply chain: two legitimate MemTensor packages on npm and PyPI were compromised to push "sckit", a Go-based credential stealer targeting Windows, Linux, and macOS. Reported by Aikido, SafeDep, Socket, StepSecurity. πŸ”— https:// thehackernews.com/2026/09/comp romised-memtensor-packages-deliver.html # SupplyChain # Malware # InfoSec

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

stream:bsky-jetstreamother5d ago kagi β†—

Threat actors are leveraging compromised MemTensor packages on npm and PyPI to distribute 'sckit,' a multi-platform Go-based credential stealer, posing a significant data theft risk to Windows… Threat actors are leveraging compromised MemTensor packages on npm and PyPI to distribute 'sckit,' a multi-platform Go-based credential stealer, posing a significant data theft risk to Windows…