Attackers compromised two legitimate MemTensor packages on npm and PyPI to spread sckit, a Go-based credential stealer targeting Windows, Linux, and macOS. Here's what you need to know.
### When Trusted Packages Turn Against You
Imagine installing a package you've used a hundred times before. Nothing looks different. The version number bumps up, you run your usual update, and life goes on. That's exactly what makes the latest MemTensor compromise so unsettling.
Unknown attackers slipped malicious code into two legitimate MemTensor libraries published on npm and PyPI. Once installed, those packages quietly drop a Go-based implant called **sckit** onto your machine. It runs on Windows, Linux, and macOS, so basically no one is off the hook.
Security teams at Aikido, SafeDep, Socket, and StepSecurity all flagged the issue. The affected library, `@memtensor/memos-cloud-openclaw-plugin`, looked normal on the surface. Underneath, it was doing something very different.
### What sckit Actually Does
sckit isn't a loud piece of malware. It's patient. It's built to sit quietly, gather credentials, and send them somewhere you'd rather they didn't go. Think of it like a houseguest who copies your spare keys instead of stealing the silverware.
A few things stand out:
- It targets multiple operating systems, not just one
- It's written in Go, which makes it portable and harder to spot
- It hides inside packages developers already trust
- It focuses on credentials, not chaos
That last point matters. Credential stealers don't crash your system or leave obvious fingerprints. They just take what they need and wait.
> "The most dangerous supply chain attacks aren't the ones that break things. They're the ones that work perfectly while stealing everything."
### Why This Keeps Happening
Here's the uncomfortable truth: package registries like npm and PyPI are built on trust. Anyone can publish. Anyone can update. And once a package has enough downloads, people stop checking.
The MemTensor case isn't unique. It's part of a pattern. Attackers compromise maintainer accounts, sneak changes into minor releases, and rely on the fact that most developers don't read every line of every dependency.
If you're running a business that depends on open-source code, and let's be honest, that's almost everyone, this should get your attention.
### What You Can Do Right Now
You don't need to panic. You do need to pay attention.
- Audit your dependencies, especially recent updates to packages you trust
- Pin versions in production so surprise updates don't sneak in
- Use lockfiles and review diffs when they change
- Monitor advisories from security firms tracking supply chain threats
- Rotate credentials if you suspect exposure
If you've recently installed or updated `@memtensor/memos-cloud-openclaw-plugin`, treat your credentials as potentially compromised. Change passwords. Revoke tokens. Check logs.
### The Bigger Picture
Supply chain attacks aren't going away. They're getting smarter, quieter, and more targeted. The packages you trust today could be weaponized tomorrow, not because the maintainers are careless, but because attackers are relentless.
Staying safe means staying curious. Ask questions. Check sources. And never assume that because something worked yesterday, it's safe today.
The sckit incident is a reminder that security isn't a one-time setup. It's a habit.