Post #23362 132 Sep 23, 2026, 12:09 UTC MemTensor npm and PyPI packages were backdoored today through their own CI pipelinehttp://safedep.io/memtensor-sckit-worm-npm-pypi@secharvester SafeDep - Real-time Open Source Software Supply Chain Security MemTensor npm and PyPI Packages Hit by a Go Worm An attacker used a Go worm to steal CI publish tokens from MemTensor and ship malicious MemOS packages to npm and PyPI. See how it works, with code and indicators of compromise.