MemTensor Packages Hit by Sckit Credential Stealer
7 Articles
7 Articles
ChainCatcher reports that, according to a security alert from SlowMist, MemTensor's AI memory toolchain has been compromised. The open-source long-term memory library MemoryOS (PyPI) for LLMs and AI agents, as well as the official plugin memtensor/memos-cloud-openclaw-plugin (npm) that connects to the OpenClaw runtime, have been compromised by a cross-platform Go binary. This malware is triggered when the package is loaded or imported. Affected …
MemTensor Packages Hit by sckit Credential Stealer
Compromised MemTensor npm and PyPI packages distributed the sckit credential stealer, putting developer machines, CI environments and cloud credentials at risk. #software, #technology, #cybersecurity, #softwaresecurity, #supplychainsecurity, #npm, #pypi, #memtensor, #flyingeze
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below @memtensor/memos-cloud-openclaw-plugin versions
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium






