Security researchers have uncovered a significant security breach involving the MemTensor packages on npm and PyPI. Unknown threat actors infiltrated these repositories to distribute a malicious Go-based implant, known as sckit, targeting Windows, Linux, and macOS platforms. This implant was embedded within certain versions of the MemTensor packages and executed when either memory integration processes or specific modules were called.
According to reports from Aikido, SafeDep, Socket, and StepSecurity, the compromised npm package versions 0.1.21, 0.1.23, and 0.1.25 were designed to launch the malicious payload during routine memory-recall events. Similarly, the PyPI package triggered the implant as soon as the memos module was imported. The primary objective of this attack was to steal sensitive credentials from cloud services, source code platforms, and developer tools, which were then sent to an external server.
Analysis by SafeDep indicated that attackers exploited the MemTensor GitHub Actions release pipelines to obtain publishing tokens, enabling them to upload the malicious versions to npm and PyPI. The implant not only collects credentials from developer machines and CI jobs but also has the capability to spread through GitHub and package publishing platforms, functioning similarly to a worm.
To mitigate the impact, developers are advised to revert to safe package versions, 0.1.20 for npm and 2.0.33 for PyPI, and rotate any exposed secrets. Additionally, it is crucial to terminate any sckit processes and block the server skyleen.fr to prevent data exfiltration. The compromised package versions have now been removed from the repositories, and clean versions are available for download.

