
highMalware
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Unknown threat actors compromised legitimate MemTensor packages on the npm and Python Package Index (PyPI) repositories, injecting a platform-specific Go-based implant dubbed 'sckit'. The malware functions as a credential stealer targeting users across Windows, Linux, and macOS operating systems. Security researchers from Aikido, SafeDep, Socket, and StepSecurity identified the compromise, which leverages the trust associated with popular machine learning package names.
The Hacker News1 min read