Supply chain operation using the sckit Go implant framework (Go module supplychain.local/campaign, C2 under skyleen.fr). First seen 2026-09-23 in the compromise of MemTensor packages @memtensor/memos-cloud-openclaw-plugin (npm) and MemoryOS (PyPI). The attacker pushed commits as the MemTensor GitHub account Memtensor-AI (victim account; how access was obtained is not confirmed) that made the project's own GitHub Actions release jobs hand the npm and PyPI publish tokens to sckit via a BASH_ENV entry written to GITHUB_ENV. Per-target campaign configs: cloud-openclaw-semi-nuclear (npm) and memos-semi-nuclear (PyPI), profile semi-nuclear, schema sckit.runtime.v1. No code or infrastructure overlap with Shai-Hulud or other public npm worms was found. Self-propagation code and templates are present in the binary (indicated by function names and strings); spreading beyond MemTensor was not observed.
Objective
Steal developer and CI credentials (including npm and PyPI publish tokens) and use them to spread the implant into further packages and repositories. Spreading objective is indicated by implant code, not observed.
Packages
Indicators
- domain skyleen.frindicates
- file_path runtime-update.ymlindicates
- domain 8a8acaf167b3.skyleen.frcommunicates-with
- domain 0b48fafd6fbe.skyleen.frcommunicates-with
- domain 266297c6df27.skyleen.frcommunicates-with
- file_path $HOME/.openclaw/.cache/runtimeindicates
- file_path lib/sckit.jsindicates
- file_path .github/scripts/sckit-publish-bridge.shindicates
- sha256 381ac6dc1715d9298fe81b2a53a11f7b7d78e361ee3a6619ad54f8c4b062cc18drops
- sha256 e077c387b223811064b7bbc5a55a0182fca9bf50894f949ff284d4be87d44b26drops
- sha256 65faf8ccbcf5b34eb4f72c71bf82815fa9c1e2f947b9c898491540e866132c31drops
- sha256 f8ccdd1da7dff1aef16377a2842bc7acf7c516e32122dd6e42dc4a4e57653fcedrops
- sha256 56cd3416d2ec2aa7e7cec2a06010cf0b58eb09c0a5486809df52afeaca8f14bedrops
- sha256 d6b3e77c36ee8017c9bf30d1da7218ec0ea843768d313eb8e35845c8a9b38a26drops
- domain c747d139e7e9.skyleen.frcommunicates-with
- domain 73376a079d87.skyleen.frcommunicates-with
- domain d4f77a3a8cb0.skyleen.frcommunicates-with
- domain 10729e014d0e.skyleen.frcommunicates-with
- url https://10729e014d0e.skyleen.fr/eb57efaa7365698fc1e4decc/initial-ci-v2communicates-with
- email [email protected]indicates
- file_path $HOME/.memos/.cache/runtimeindicates
- file_path memos/_stage0.pyindicates
- file_path src/memos/_pypi_bridge.shindicates
- file_path sckit_poetry_build.pyindicates
- sha256 c1b0998347b489582bae7b7f4930f9831d9ef4b6bc150cfd488ee1a43272dd36drops
- sha256 8f647f17a1934679c4095e21bee2b9bd83e28476603758bc91408a0c8443e3b4drops
- sha256 9de0d5b0ca184f71f630be5781d134998883a02d5d7bc65aeb9559d8f9efb364drops
- sha256 5405e330507602e803f7dd6f2a9d4555aec8558ab222b51413594a962da6888adrops
- sha256 16de381deb978744535b10f68fe15165251374b86eef18ffc2c47f61ea673047drops
- sha256 f7c4014e284f3d56c452b8b222a287c54f73dc4a40a7e022e765ac8376362947drops
Techniques
- ttp T1195.002 Compromise Software Supply Chainuses
- ttp T1528 Steal Application Access Tokenuses
- ttp GITHUB_ENV BASH_ENV Injectionuses
- ttp T1059.004 Unix Shelluses
- ttp T1059.007 JavaScriptuses
- ttp T1480 Execution Guardrailsuses
- ttp T1070.004 File Deletionuses
- ttp T1071.001 Web Protocolsuses
- ttp T1552.001 Credentials In Filesuses
- ttp T1082 System Information Discoveryuses
- ttp T1614 System Location Discoveryuses
- ttp T1573 Encrypted Channeluses
- ttp T1041 Exfiltration Over C2 Channeluses
- ttp T1059.006 Pythonuses
- ttp T1105 Ingress Tool Transferuses