The record
Written from the 1 report below. Nothing here is unsourced.
- Threat actors compromised specific versions of MemTensor libraries hosted on npm and PyPI repositories.
- These packages contain a Go-based implant named sckit that executes upon installation or integration.
- The malware harvests sensitive credentials from developer workstations and CI/CD pipelines including API keys and authentication tokens.
- Stolen information is exfiltrated to a command-and-control server.
What to watch next
- Discovery of additional impacted software packages beyond MemTensor.
- Evidence of further self-proliferation through GitHub and package registries.
- Updates on the removal of malicious package versions from npm and PyPI.
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
StepSecurity
1 quote · 1 outlet
“The launcher passes the host process environment and, during recall, the user's prompt text directly to the malicious executable.”
In the article
…a legitimate AI memory integration. Versions 0.1.21, 0.1.23, and 0.1.25 contain code that launches the payload when the agent gateway starts and whenever the plugin handles a memory-recall event," StepSecurity said. " The launcher passes the host process environment and, during recall, the user's prompt text directly to the malicious executable. " The PyPI package, on the other hand, starts the statically-linked Go binary as soon as the "memos" module is imported into an application. Regardless of the ecosystem targeted, the end goal is to launch a…
Coverage1
All filed from India
Named United States · AWS · GitHub · GitLab · HashiCorp Vault · MemTensor · Aikido · SafeDep · skyleen.fr · Socket · StepSecurity
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
