Compromised AI Packages Execute Malware on Import, Security Firm Warns
Security firm Socket identified compromised Python and npm packages that executed malicious binaries immediately upon import, without requiring any function calls. The affected packages, including MemTensor and an OpenClaw plugin, launched hidden processes that could search for credentials and communicate with attacker-controlled servers. Socket's analysis found these packages contained cross-platform Go binaries named 'sckit' that activated when the libraries were loaded. The firm advises using isolated environments to inspect package artifacts before deployment, as traditional functional testing occurs too late. They recommend checking for unauthorized native binaries, permission changes, and unexpected size increases in packages.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in