23-09-2026
MemTensor npm and PyPI Packages Compromised in Credential-Stealing Supply Chain Attack
https://socket.dev/blog/memtensor-compromise
Report completeness: Medium
Threats:
Supply_chain_technique
Credential_stealing_technique
Sckit_tool
Victims:
Software developers, Npm, Pypi, Github, Gitlab, Aws, Vault, Ssh users
TTPs:
Tactics: 2
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1005, T1041, T1083, T1195.001, T1195.002, T1552.001, T1552.004, T1573
IOCs:
Domain: 8
File: 9
Url: 1
Hash: 14
Soft:
OpenClaw, Linux, macOS, Hugging Face, HashiCorp Vault, Slack, SendGrid
Algorithms:
sha256, base64
Functions:
launchStageZero, configure_logging, get_logger, trigger
Languages:
python
Platforms:
x64, cross-platform, arm