Vulnerability  ·  2026-09-27

sckit: first supply-chain worm targeting AI-agent memory infrastructure — compromised MemTensor npm/PyPI packages drop Go credential stealer

VulnerabilityHigh impactGlobal
Threat actors compromised two legitimate MemTensor packages and delivered sckit on both npm and PyPI. Multiple researchers (StepSecurity, SafeDep, Socket, Aikido) documented the campaign on 2026-09-23, amplified through the 09-25/26 window as the first documented supply-chain worm directly targeting agent memory infrastructure. Malicious versions have been yanked; safe versions are 0.1.24 (npm) / 2.0.33 (PyPI).
Agent memory infrastructure sits inside the highest-credential-density process in modern dev/CI environments. Because the payload triggers on memory recall (not install), merely using an affected agent leaks prompts and inherited credentials, and the embedded self-propagation routines threaten the broader npm/PyPI/GitHub ecosystem. Pin to clean versions, rotate all credentials reachable from affected hosts, and block skyleen[.]fr.
Malicious npm/PyPI releases (published 2026-09-23 via compromised maintainer publish tokens) bundle a cross-platform Go executable (sckit) launched through legitimate plugin code paths (lib/sckit.js on npm; memos/log.py import-time hook on PyPI) — no install scripts, evading standard scanning. It harvests npm/PyPI/GitHub/GitLab tokens, AWS keys, Hugging Face/Vault/Slack/Stripe/SendGrid keys, SSH keys, JWTs and secret-shaped env vars, exfiltrating to skyleen[.]fr; embedded functions (recursivePublish, prepareRemote*) enable worm-like self-propagation through package registries.
Pin @memtensor/memos-cloud-openclaw-plugin to 0.1.24 (or 0.1.20 baseline) and MemoryOS to 2.0.33; remove the packages; rotate registry/source-control/cloud/Vault/SSH credentials; kill any 'sckit' process; block skyleen[.]fr and subdomains.
StepSecurity: Sckit supply-chain worm analysisThe Hacker News: Compromised MemTensor packages deliver sckitForkast: First supply-chain worm targeting AI agent memory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →