MemTensor npm and PyPI Packages Hit by a Go Worm (opens in a new tab)
Why readNames the compromised packages and indicators for a self-propagating Go implant: @memtensor/memos-cloud-openclaw-plugin on npm and MemoryOS on PyPI, credential exfiltration to skyleen[.]fr, and publish tokens stolen from MemTensor's own GitHub Actions release pipeline.
On 23 September 2026 an attacker published trojanised MemTensor releases to npm and PyPI carrying the same Go implant, sckit, which executes on every package load, harvests credentials from the user's home directory and ships them to skyleen[.]fr. The implant also carries the code to republish itself into any other repository or package those stolen credentials can reach, making it a worm rather than a single poisoning. Initial access came from commits that caused the release job to hand its npm or PyPI token to the attacker before publishing; the tell that surfaced it was versions 0.1.21 and 0.1.23 not matching any commit in the repository. Check your lockfiles and rotate any registry tokens reachable from affected build agents.
Indicators12
- Hashes
d9169ce8f4faaa663bf5f44918b5612ed9f933ba18987207dc4ab412733d51645dbc82475ce61369e53f795f0a44451715763450051fa2a84d38d6b2e8700114c1b0998347b489582bae7b7f4930f9831d9ef4b6bc150cfd488ee1a43272dd36995a208944176c437a023f4a5c11baad2eb77a91847893c82e5866eaabedb8106caf89b059e9b6c82bb4ac4727816d516753c4d26833434dea0ecda44a346eb3a6870826cd7c7ec8d32af227252efcdcdca03ac956d4702cdc2157ca8264167339ee644406829a4b630b31759c20478bc22d576d6a59b253ed86f72c360aa5ef92b46d18fc553c494eda714f204459edb74c205bf53b18a9092bcf02c7a6c5be381ac6dc1715d9298fe81b2a53a11f7b7d78e361ee3a6619ad54f8c4b062cc18e077c387b223811064b7bbc5a55a0182fca9bf50894f949ff284d4be87d44b268f647f17a1934679c4095e21bee2b9bd83e28476603758bc91408a0c8443e3b465faf8ccbcf5b34eb4f72c71bf82815fa9c1e2f947b9c898491540e866132c31
Also covered byStepSecurity (CI/CD) (opens in a new tab),Aikido Security (opens in a new tab).