Campaign to supply infected npm and PyPI packages with Go sckit binary and credentials theft

Author: Published 6 min de lectura 13 reading

The images in this article were generated with artificial intelligence. How we publish

A package supply campaign has recently compromised legitimate components used by developers and continuous integration pipelines to distribute a malicious multiplatform tool. The attackers inserted a Go binary called "sckit" into specific versions of a npm package and a PyPI package, and the malicious code is automatically activated when loading the dependency or processing memory events in running time. Reports from Aikido, SafeDep, Socket and StepSecurity confirm the involvement of versions 0.1.21, 0.1.23 and 0.1.25 of the npm @ memtensor / memos-cloud-openclaw-plugin package and version 2.0.34 of the PyPI MemoryOS package (the latter has been quarantine in PyPI). The npm package is available in your public register at npmjs.com and the affected entry of the Python ecosystem in pypi.org.

In what is verified so far, malicious versions include a charger that launches the Go binary when the plugin is initialized (in the case of npm) or when the "memos" module is imported (in PyPI). The executable is compiled in a static way and acts as a credentials thief: it collects configuration files and tokens (.npmrc, .vault-token, id _ ecdsa, credentials.db, access _ tokens.json, stored _ tokens), environment variables containing keys (NPM _ TOKEN, PIPI _ API _ TOKEN, etc.), and service keys or tokens such as AWS, GitHub, GitLab, Huging Face, and Hashipe, Slack, and Grid. The malware exfiltrates this information to a command and control server hosted under the domain reported by analysis signatures like skyleen.fr.

Campaign to supply infected npm and PyPI packages with Go sckit binary and credentials theft
Image generated with IA.

Technically, how the intrusion works: The initial vector was the malicious publication of new versions of legitimate libraries. SafeDep documents that the attackers were able to publish these packages using publication tokens available in the GitHub Actions of the MemTensor project; in particular, they introduced commitments that fired workflows that exposed or facilitated the use of the publication token. Once the package is distributed, the binary sckit is run in the context of the process that loads the dependency, allowing you to inherit environment variables and access to the same user and file system as the CI application or job where the dependence was imported.

In addition, the malware analysis indicates self-propagation capabilities: templates and mechanisms to insert the payload into Npm packages, Python packages and GitHub Actions workflows, which allows you to behave in a worm- like way and publish for yourself new malicious versions if you get valid tokens. In practical terms, this means that a team with access to repositories, publication credentials or workflows with excessive privileges could facilitate the automatic spread to other projects and accounts.

Who are the affected and why it matters: the primary victim are the developer machines and the CI jobs that install or import the compromised versions. Since the plugin affects a component designed to be integrated into "memory" agents for IA tools and runtime agents, infected processes usually handle user text, prompts and temporary or permanent credentials, so the exposure may include injected secrets for a specific task. In practice, this puts at risk repositories, cloud service accounts, package tokens and the secrets used by pipelines, with the potential for climbing (reuse of credentials, publication of malicious versions, lateral movement in CI / CD infrastructures).

Facts confirmed: The noted versions of the packages contain the malicious binary and launcher; the reported exfiltration domain is skyleen.fr; the technique of obtaining the publication token involved GitHub Pipels Actions of the project; PyPI has quarantined the affected version. Estimates and elements still uncertain: the total scope (if there are other packages committed in addition to MemTensor), the authorship of the actor who put the payload and the number of organizations affected is not fully confirmed. The analyses also suggest, but do not guarantee, that the campaign is designed to self-spread when it gets sufficient credentials.

What a development team or organization should do now: action is urgent and concrete. First, paint dependencies to secure versions: for package npm, return to version 0.1.20; for PyPI, to 2.0.33, according to available analyses. Second, immediately revoke and rotate any credential that may have been in the process environment (npm / PyPI tokens, AWS keys, GitHub / GitLab tokens, Vault secrets, etc.). Third, search and stop suspicious processes called or that run "sckit" and remove unrecognized binary in development environments and CI runners; also block the C2 domain and its subdomains at network and proxy level (skyleen.fr and variants).

Recommended technical detection and containment actions: search for "skyleen" and binary names in repositories and artifacts: grep -R "skyleen." / var & ps aux-124; grep sckit-124;-124; true; check tokens files (.npmrc, credentials.db, .vault-token, id _ ecdsa) for recent modifications, compare checksums with expected buildings, review GitHub Actions logos in unauthorised settings and search for unauthorised repositories and / or replacements. Check which accounts and workflows have publication permits and remove publication tokens embedded in repositories; instead, use temporary federation mechanisms such as OIDC and principles of less privilege (see GitHub's guide to OIDC: Setting OpenID Connect in your workflow).

Campaign to supply infected npm and PyPI packages with Go sckit binary and credentials theft
Image generated with IA.

Medium-term mitigation measures: enable the scanning of secrets in commit and artifacts, force 2FA into relevant accounts, restrict permits of CI runners, rotate long-use keys to short-term credentials, audit and limit publication tokens, generate SBOMs and sign artifacts and releases to detect unauthorized modifications. It is also key to review third-party integration points (bots, plugins, memory agents) and treat units as assets that require change control and integrity verification.

Finally, should not be assumed that the incidence is contained until a forensic review is completed. If your organization used the compromised versions, proceed with the rotation of secrets, a thorough search for pollution in repositories and runners, and a reconstruction of artifacts from clean sources. If you detect unauthorized publications made by your accounts or workflows, immediately investigate and, if necessary, contact the registration providers (npm, PyPI, GitHub) for assistance in mediation and reporting.

The episode highlights that automated pipelines and publishing tokens are a critical target for adversaries interested in compromising the software supply chain. The combination of multi-platform binaries and mechanisms to inherit the context of execution converts popular dependencies into extremely powerful vectors: prevention requires both technical controls (least privilege, ODC, rotation of secrets) and operational (commitment reviews, CI monitoring, malicious domain blocking and rapid forensic responses).

Coverage

Related

More news on the same subject.