The ‘sckit’ Worm Bridges the npm and PyPI Divide

Cross-platform sckit worm infection vector bridging npm and PyPI ecosystems via MemTensor packages

An identical, highly sophisticated malicious program has successfully breached both sides of a major programming language divide simultaneously. On September 23, deeply infected releases of the MemTensor packages inexplicably materialized within both the npm (Node.js) and PyPI (Python) registries. Concealed deep within these compromised distributions lurked sckit, a remarkably versatile, cross-platform worm written in Go. The cybersecurity firm Aikido, which spearheaded the discovery, officially christened the campaign supplychain.local, a nomenclature derived directly from a specific module embedded within the malicious binary itself. Alarmingly, prior to this coordinated assault, both targeted packages had maintained a lengthy history of publishing entirely legitimate, uncompromised versions.

Within the expansive npm ecosystem, the specific casualty was the @memtensor/memos-cloud-openclaw-plugin. The malicious payloads were meticulously injected into versions 0.1.21, 0.1.23, and 0.1.25. Conversely, within the PyPI environment, the malignant code infiltrated the MemoryOS package, specifically targeting version 2.0.34. Curiously, nestled securely between the infected npm releases were perfectly pristine, uncompromised versions (0.1.22 and 0.1.24). Crucially, at the precise moment of their discovery, these malicious builds represented the absolute latest available versions. Consequently, a standard, default installation command executed by an unsuspecting developer would effortlessly pull down the infected code without requiring any explicit version designation.

Execution Evasion and Relentless Credential Harvesting

The true, insidious brilliance of this attack resided in its meticulously orchestrated execution trigger. The sckit worm deliberately eschewed standard installation hooks such as preinstall or postinstall, ensuring it remained completely dormant during the initial package installation phase. Within the compromised npm plugin, the malicious binary only activated during the operational launch of OpenClaw and subsequent memory access operations. Similarly, within the infected MemoryOS package, activation was delayed until the developer explicitly imported the Python library. Therefore, employing defensive parameters like --ignore-scripts proved entirely ineffective at blocking the malware, and superficial scans focusing exclusively on installation hooks would invariably fail to detect its presence. For an in-depth analysis of this evasion tactic, you can read the Aikido blog post regarding the supplychain.local MemTensor attack on npm and PyPI.

Immediately upon activation, sckit ruthlessly scoured the victim’s home directory and active process environments, desperately hunting for sensitive cryptographic secrets. Its primary targets included authentication tokens for npm, PyPI, GitHub, and GitLab, alongside AWS access keys and SSH private keys. Furthermore, it actively sought credentials associated with HashiCorp Vault, Hugging Face, Slack, Stripe, and SendGrid. Obtaining uninhibited access to this treasure trove of data empowered the attacker to seamlessly pivot from a single compromised workstation directly into sensitive corporate repositories, proprietary software packages, and expansive cloud infrastructure.

Automated Proliferation via Stolen Tokens

Security researchers at SafeDep meticulously reconstructed the attack chain, tracing it back through the official GitHub Actions workflows of the MemTensor project itself. The adversaries had stealthily injected code designed to intercept the NPM_TOKEN and PYPI_API_TOKEN at the exact moment preceding a legitimate release publication. For the npm infiltration, they leveraged ephemeral, short-lived branches that were rapidly created and subsequently destroyed multiple times. For PyPI, they prepared unsigned, anomalous commits operating entirely outside the primary development branch. The precise mechanism by which the attacker initially obtained write access to the repository remains unconfirmed. For additional technical context, you can review the SafeDep analysis of the MemTensor sckit worm in npm and PyPI.

The stolen cryptographic keys rapidly transformed the infected workstation—or the compromised CI/CD environment—into a formidable new distribution hub. Deep within the sckit binary, analysts discovered explicit commands to execute npm publish and npm version patch, alongside instructions for uploading payloads to PyPI via twine. Furthermore, they unearthed a malicious GitHub Actions template explicitly designed to execute the implant following every subsequent code push. Empowered by these stolen credentials, the malware possessed the terrifying capability to autonomously publish new, infected package versions and seamlessly transmit the infection across the two distinct ecosystems.

Assessing the Impact and Current Mitigation Status

This sophisticated propagation mechanism bears a striking resemblance to historical, large-scale supply chain attacks targeting npm, where exfiltrated developer tokens were weaponized to publish catastrophic new infected versions. For instance, earlier this summer, the notorious Mini Shai-Hulud worm propagated aggressively across hundreds of npm packages, ruthlessly harvesting secrets directly from developer environments[cite: 1.2]. The supplychain.local campaign significantly expanded upon this proven methodology by concurrently targeting PyPI and meticulously preparing versatile binaries compatible with Windows, Linux, and macOS across both x64 and ARM64 architectures.

Fortunately, the currently confirmed blast radius remains strictly confined to the two identified MemTensor packages. Aikido has not yet discovered any public repositories where sckit successfully embedded its prepared GitHub Actions workflows or deployed its auxiliary JavaScript and Python loaders. While the code undeniably possesses the theoretical capability for autonomous self-propagation, there was absolutely no concrete evidence of a massive, cascading chain infection at the time of the initial forensic analysis. Furthermore, no new, definitively infected packages have been confirmed.

As of September 28, the infected npm releases (0.1.21, 0.1.23, and 0.1.25) have been completely expunged from the registry, and the crucial latest tag now safely points to the pristine 0.1.24 version. Similarly, PyPI currently displays MemoryOS version 2.0.33 as the latest available, safe release. SafeDep vehemently advises any users who inadvertently installed the infected builds to immediately uninstall the compromised package, forcibly terminate all active sckit processes, meticulously audit their repositories for unauthorized workflow modifications, and aggressively rotate every single cryptographic key and authentication token accessible to the infected system.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply