Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
The Hacker News reported on September 23, 2026 that compromised MemTensor packages delivered a credential stealer named sckit through npm and PyPI. According to the source, the malicious code was distributed via packages published to both registries, meaning the same campaign touched the JavaScript and Python package ecosystems. The payload is described as a credential stealer, indicating the compromised packages were used to obtain credentials rather than, for example, to mine cryptocurrency or deploy ransomware. The source does not specify which MemTensor package names or versions were affected, how long the compromised releases remained available, how many downloads occurred, or whether the packages have been removed. It also does not describe the stealer's collection targets, command-and-control infrastructure, or the identity of the actors behind the compromise. No remediation guidance, indicators of compromise, or victim counts are provided in the excerpt. The report is limited to identifying the compromised MemTensor packages, the two distribution channels (npm and PyPI), and the sckit credential stealer as the delivered payload.
It shows developers that packages they install from npm or PyPI can carry credential-stealing code, reinforcing that dependency trust is not guaranteed by the registry.