# Compromised MemTensor npm and PyPI packages deliver a Go credential stealer to developer machines

> Aikido, SafeDep, Socket and StepSecurity report that hijacked MemTensor packages install sckit, a Go stealer for tokens and keys on Windows, Linux and macOS.

FireAI Security & Research Team (HisnLabs) · Published 2026-09-30
Canonical: https://hisnlabs.com/en/news/memtensor-npm-pypi-packages-sckit-credential-stealer

Security firms Aikido, SafeDep, Socket and StepSecurity report that attackers published poisoned versions of MemTensor packages on npm and PyPI that install sckit, a Go-based stealer for developer credentials, [The Hacker News reported](https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html) on 23 September. The stealer runs on Windows, Linux and macOS.

## Background

Package registries let developers install other people's code with one command, and an install can run code on the developer's own computer. Attackers who obtain a maintainer's publishing token can therefore reach every machine that installs their version [[1]](https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html).

## What the report describes

The affected packages are @memtensor/memos-cloud-openclaw-plugin on npm, versions 0.1.21, 0.1.23 and 0.1.25, and MemoryOS on PyPI, version 2.0.34. The report says the attackers obtained publishing tokens by compromising MemTensor's GitHub Actions release pipelines and pushed malicious versions between clean releases [[1]](https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html).

In the npm plugin, the hidden payload starts when the agent gateway starts or during memory-recall events. In the PyPI package it starts when the module is imported. Both run a statically linked Go program that gathers API tokens, SSH keys, cloud configuration files and environment variables tied to services such as npm, PyPI, GitHub, GitLab, AWS and Vault, and sends them to an external server. The report describes the implant as a worm able to spread through GitHub repositories and package registries [[1]](https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html).

The malicious versions have been removed. The report lists 0.1.24 on npm and 2.0.33 on PyPI as the latest clean releases, and advises pinning to 0.1.20 on npm and 2.0.33 on PyPI [[1]](https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html).

> A stolen key is only useful once it leaves the machine. FireAI, the on-device firewall for macOS developed by HisnLabs, asks before an app with no rule connects out. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for Mac users

Developers who installed the listed versions on a Mac are exposed to the theft of any secrets stored in the locations above. People who do not use these packages are not affected as reported. Anyone who installed a listed version needs to treat the credentials on that machine as exposed [[1]](https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html).

## Recommendations

1. Check lockfiles and installed packages for the versions named above and remove them.
2. Rotate every credential the machine could reach: tokens for npm, PyPI and GitHub, SSH keys, cloud keys and secrets in environment variables.
3. Revoke tokens as well as changing passwords, as the report advises rotating exposed secrets.
4. Pin dependencies to known clean versions, as the report suggests, and review release-pipeline permissions for maintained packages.

## Relevance to FireAI

FireAI does not inspect packages or remove an implant. The stolen data has to be sent to a server, and a new Go program with no rule triggers a connection prompt in Alert mode, with the destination shown on the [world map](https://hisnlabs.com/en/docs/world-map). [Per-app rules](https://hisnlabs.com/en/docs/per-app-rules) let a build tool or interpreter be limited to the hosts it needs. If a build tool already has a broad Allow rule, FireAI would not ask, so such rules need to be narrow.

> Give build tools and scripts only the destinations they need. FireAI lets a per-app rule limit each one. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

The report does not say how many machines installed the poisoned versions, how long each was live, or who is behind the campaign. Its description of worm behaviour comes from the researchers' analysis.

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [The Hacker News, 23 September 2026: Compromised MemTensor packages deliver the sckit credential stealer](https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html)
