Malicious 'sckit' Package Found Hidden in MemOS AI Framework on npm and PyPI
Security researchers discovered a supply chain attack in which a malicious component called 'sckit' was embedded within legitimate MemTensor MemOS releases distributed through npm and PyPI package registries. Unlike typical malware, the payload does not activate during installation but instead triggers when affected Python packages are imported, the OpenClaw gateway is started, or a memory-recall hook is invoked. Once active, platform-specific binaries scan developer workstations, CI runners, and OpenClaw hosts for credentials including tokens from GitHub, npm, PyPI, cloud services, and Slack, then transmit stolen data to domains under skyleen.fr. The attack was rated critical severity by Semgrep, which published its analysis on September 23, 2026, with corroborating findings from Aikido and StepSecurity. Organizations are advised to block affected package versions, rotate credentials, use short-lived tokens in CI pipelines, and restrict outbound connections to unapproved domains.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in