The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In September 2026, unknown threat actors compromised legitimate MemTensor packages across npm and PyPI repositories, injecting a cross-platform Go-based credential stealer called 'sckit'. The malware targeted @memtensor/memos-cloud-openclaw-plugin versions 0.1.21, 0.1.23, and 0.1.25 on npm, and MemoryOS version 2.0.34 on PyPI. The implant harvested sensitive credentials from cloud services, source-code platforms, package registries, and developer tools, exfiltrating data to skyleen[.]fr. The attackers obtained publish tokens from MemTensor's GitHub Actions pipelines and designed the malware to self-proliferate like a worm through GitHub and direct package publishing.

This incident highlights the growing sophistication of supply chain attacks targeting AI and machine learning ecosystems, where attackers increasingly exploit trusted development pipelines and package repositories to distribute credential-stealing malware at scale.

Why This Matters Now

AI development supply chains are becoming prime targets for sophisticated attackers who exploit the trust developers place in ML packages and the high-value credentials typically present in AI development environments.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers obtained publish tokens from MemTensor's GitHub Actions release pipelines by pushing commits that caused the workflow to hand over npm and PyPI tokens.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained this supply chain attack by limiting lateral movement between development environments and reducing the blast radius of compromised credentials through segmented network access and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: CNSF visibility would likely have detected anomalous workflow execution patterns and unauthorized token exposure within the CI/CD pipeline environment, potentially constraining the scope of credential harvesting activities.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust segmentation would likely have limited the reach of compromised publishing tokens by restricting network access from CI/CD environments to external package repositories based on identity and policy verification.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have constrained malware propagation between developer workstations and CI environments by enforcing segmented communication paths and workload isolation policies throughout the development infrastructure.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls would likely have detected and constrained unauthorized outbound communications to the C2 infrastructure, limiting the malware's ability to receive remote commands and coordinate harvesting activities across cloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security policies would likely have constrained unauthorized data transmission to external servers by blocking or limiting outbound connections from compromised workloads, reducing the scope of credential exfiltration activities.

Impact (Mitigations)

Even with some credential compromise, Zero Trust segmentation would likely have reduced the blast radius of unauthorized access by limiting credential scope and constraining lateral movement across cloud services and development infrastructure.

Impact at a Glance

Affected Business Functions

  • Software Development
  • CI/CD Pipelines
  • Package Management
  • Credential Management
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: N/A

Data Exposure

Developer credentials including npm tokens, PyPI API tokens, GitHub and GitLab tokens, AWS access keys, SSH private keys, HashiCorp Vault tokens, and various API keys for services like Slack, Stripe, and SendGrid. Environment variables containing passwords, database connection strings, and session cookies were also harvested.

Recommended Actions

  • • Implement Zero Trust Segmentation to isolate CI/CD environments and prevent lateral movement between development infrastructure components
  • • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections to domains like skyleen[.]fr and detect credential exfiltration attempts
  • • Enable Multicloud Visibility & Control to monitor package installation activities and detect anomalous automation behaviors in development workflows
  • • Establish Cloud Native Security Fabric (CNSF) controls to provide real-time inspection of package imports and inline enforcement against malicious payloads
  • • Deploy Threat Detection & Anomaly Response capabilities to baseline normal development activities and alert on credential harvesting behaviors or unusual package execution patterns

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image