CONNECT WITH US
Cyber Security

Cyber Security

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News logo

Published on

Add as a preferred source on Google
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.

According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below -

The malicious npm package versions include a "hidden Go payload into a legitimate AI memory integration. Versions 0.1.21, 0.1.23, and 0.1.25 contain code that launches the payload when the agent gateway starts and whenever the plugin handles a memory-recall event," StepSecurity said.

"The launcher passes the host process environment and, during recall, the user's prompt text directly to the malicious executable."

The PyPI package, on the other hand, starts the statically-linked Go binary as soon as the "memos" module is imported into an application.

Regardless of the ecosystem targeted, the end goal is to launch a cross-platform credential-stealing payload capable of harvesting sensitive data from cloud services, source-code platforms, package registries, and developer tools and exfiltrating the details to an external server ("skyleen[.]fr").

According to Socket, targets include npm, PyPI, GitHub, GitLab, AWS, Vault and SSH secrets -

SafeDep, in its analysis of the supply chain attack, said the attacker obtained the publish tokens from MemTensor's own GitHub Actions release pipelines by pushing commits that caused the workflow to hand over the npm or PyPI token.

A deeper examination of the implant suggests that it can function like a worm by self-proliferating through GitHub and direct npm and PyPI package publishing.


Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We TheMorningPulse.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It's possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.