sckit

discovered 2026-09-23

Supply chain operation using the sckit Go implant framework (Go module supplychain.local/campaign, C2 under skyleen.fr). First seen 2026-09-23 in the compromise of MemTensor packages @memtensor/memos-cloud-openclaw-plugin (npm) and MemoryOS (PyPI). The attacker pushed commits as the MemTensor GitHub account Memtensor-AI (victim account; how access was obtained is not confirmed) that made the project's own GitHub Actions release jobs hand the npm and PyPI publish tokens to sckit via a BASH_ENV entry written to GITHUB_ENV. Per-target campaign configs: cloud-openclaw-semi-nuclear (npm) and memos-semi-nuclear (PyPI), profile semi-nuclear, schema sckit.runtime.v1. No code or infrastructure overlap with Shai-Hulud or other public npm worms was found. Self-propagation code and templates are present in the binary (indicated by function names and strings); spreading beyond MemTensor was not observed.

Objective

Steal developer and CI credentials (including npm and PyPI publish tokens) and use them to spread the implant into further packages and repositories. Spreading objective is indicated by implant code, not observed.

Packages

Indicators

Techniques

Read the full analysis →