MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-23 · via The Hacker News

Supply-Chain Attack on MemTensor Packages Delivers Cross-Platform Credential Stealer

Image via The Hacker News
Image via The Hacker News

Attackers compromised two legitimate MemTensor packages on npm and PyPI to distribute a Go-based implant named sckit. The malware targets Windows, Linux, and macOS. Multiple security firms reported the incident.

Expanded Detail

The compromise of two legitimate MemTensor packages on the npm and PyPI registries marks a notable escalation in software supply-chain tactics. By injecting a Go-based implant named sckit into trusted code, the attackers gained a foothold across all major desktop operating systems—Windows, Linux, and macOS—without requiring users to seek out malicious software. The campaign was uncovered through coordinated reporting by multiple security firms, underscoring how widely distributed package ecosystems can be abused to reach downstream developers and their applications.

Such incidents highlight the persistent risk inherent in open-source dependency management. Even well-maintained packages can be silently altered, and the cross-platform nature of the payload broadens the potential victim pool. For organizations relying on these registries, the event serves as a reminder that verification and monitoring of third-party code remain critical, though the full scope of the compromise has not been disclosed.

Context

This attack could affect developers and organizations that unknowingly integrated the compromised packages, potentially exposing credentials and sensitive systems. Because the implant runs on multiple operating systems, the reach may extend across personal and enterprise environments. If credentials are stolen, downstream users—from individual programmers to large firms—could face unauthorized access or data breaches. The incident may also erode trust in open-source registries, prompting stricter vetting but also increasing caution among smaller teams with limited security resources.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
AI-Powered Malware 'ClosedQuorum' Automates Post-Compromise Actions on Windows · Cybersecurity
NPM Package 'indexed-btree' Hides Malware in Runtime Function to Bypass New Security Controls · Cybersecurity
Go Malware Delivered via Malicious Terraform Providers and Go Modules · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI.” Browse more stories.