The MemTensor compromise turned trusted npm and PyPI packages into a cross-platform credential-stealing supply-chain threat targeting developer environments and automation workflows.
Malicious releases delivered sckit, targeting cloud credentials, repository tokens, package publishing tokens, Vault tokens, SSH keys, and other secrets.
Security teams should identify affected versions, contain suspicious execution, rotate exposed credentials, rebuild from trusted dependencies, and audit downstream repository, package, workflow, and cloud activity.
Hexnode XDR can support endpoint investigation and containment through Isolate Device, Kill Process, and Quarantine File, while credential and CI recovery require separate remediation.
The MemTensor compromise turned legitimate AI memory packages into a credential-theft channel. Malicious releases on npm and PyPI delivered sckit, a Go-based stealer targeting Windows, Linux, and macOS. For security administrators, the exposure spans developer workstations, agent gateways, and automation environments.
These integrations can run with access to prompts, repositories, and credentials. That makes package execution an enterprise security concern, particularly when developers reuse privileged accounts across tools.
How the MemTensor compromise reaches developer environments
Researchers identified malicious releases of two packages:
Package
Affected versions
Additional findings
@memtensor/memos-cloud-openclaw-plugin on npm
0.1.21, 0.1.23, 0.1.25
Researchers reported 0.1.22 and 0.1.24 clean.
MemoryOS on PyPI
2.0.34
PyPI quarantined the project.
The September 23 reporting identifies the affected releases and quarantine status. Teams should check resolved dependency versions rather than assuming every release within the same range is malicious.
The npm plugin launches its hidden payload when the agent gateway starts and during memory-recall events, passing the user’s prompt and environment data to the executable. Meanwhile, the Python package triggers execution when the application configures logging via memos.log.configure_logging().
Featured Resource
Cybersecurity kit
Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.
The stealer targets credential files and environment variables containing cloud keys, registry tokens, and other secrets. Targets include AWS credentials, GitHub and GitLab tokens, npm and PyPI publishing tokens, Vault tokens, SSH keys, Hugging Face tokens, and JSON Web Tokens (JWTs). Researchers identified skyleen[.]fr as exfiltration infrastructure.
SafeDep traced publishing-token theft to MemTensor’s GitHub Actions release pipelines. Its analysis also found templates for spreading through npm packages, Python packages, and GitHub Actions workflows. These findings indicate propagation capability; they do not establish the full extent of infections beyond MemTensor.
For enterprises, this creates a second exposure path: stolen publishing credentials could put downstream consumers at risk.
What security teams should do now
Start with package exposure, then expand the investigation to every identity available during execution.
Locate affected installations. Review lockfiles, build records, developer environments, agent gateways, and CI images. Record package versions, execution times, and responsible owners.
Contain suspicious execution. Investigate sckit processes and connections to the reported domain. Preserve process details, relevant logs, and payload hashes before cleanup.
Revoke and rotate exposed secrets. Include credentials injected into jobs and secrets accessible through local files. Perform rotation from a trusted environment.
Restore a verified dependency baseline. Remove malicious releases and rebuild affected environments from trusted inputs. Check caches and reusable images before restarting jobs.
Audit downstream activity. Review repository changes, workflow modifications, package publications, and cloud activity associated with exposed identities.
Treat these as coordinated response steps. A dependency rollback alone cannot revoke a stolen token or undo unauthorized publications. Assign endpoint, cloud, and development owners to the same investigation so cleanup and credential recovery proceed together.
How Hexnode supports endpoint investigation and containment
Hexnode can support the endpoint portion of this response on supported, enrolled devices.
Hexnode UEM compliance policies help administrators assess devices against configured requirements and identify posture gaps for follow-up. Compliance status should inform endpoint hygiene decisions; it does not certify that an npm or Python dependency is safe.
While sckit targets Windows, macOS, and Linux, Hexnode XDR’s Visual Process Tree and one-click remediation actions operate on Windows and macOS endpoints. Administrators can investigate process relationships and initiate Isolate Device, Kill Process / Kill Process Tree, and Quarantine File actions. Linux endpoints are managed through Hexnode UEM policy actions.
Response objective
Hexnode XDR action
Restrict an affected endpoint’s connectivity
Isolate Device cuts network access while maintaining the endpoint’s connection to the Hexnode console for ongoing forensic investigation.
Stop malicious processes
Kill Process / Kill Process Tree terminates a selected process or its process tree, respectively.
Contain a malicious payload
Quarantine File blocks and encrypts the file for review.
These administrator-initiated actions support containment. Credential revocation, package verification, and CI recovery still require coordination with the teams operating those systems.
FAQs
How can organizations tell whether they installed a malicious MemTensor package?
Teams should check resolved dependency versions in lockfiles, build records, developer environments, agent gateways and CI images. The reported malicious releases include @memtensor/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23 and 0.1.25, plus MemoryOS version 2.0.34.
What credentials can the sckit malware steal?
sckit targets credential files and environment variables containing secrets such as AWS credentials, GitHub and GitLab tokens, npm and PyPI publishing tokens, Vault tokens and SSH keys. Security teams should assess which credentials were accessible wherever an affected package executed.
Protect the secrets behind AI integrations
AI integrations inherit software supply-chain risks while introducing access to agent context and prompts. Reduce that exposure through reviewed dependencies, limited credential access, and monitored execution. When compromise occurs, contain affected endpoints and revoke exposed credentials together.
Strengthen Software Supply Chain Defense
Protect developer endpoints, detect credential theft, and contain supply-chain threats faster with Hexnode UEM and XDR.
Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.