Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware appears to publish to npm via npm publish and npm version patch and to PyPI via twine upload using credentials stolen from infected workstations or CI environments.
The attacker obtained the publish tokens from MemTensor's own GitHub Actions release pipelines by pushing commits that caused the workflow to hand over the npm or PyPI token. | Unknown threat actors compromised legitimate MemTensor packages across npm and PyPI, inserting a hidden Go payload into otherwise legitimate package releases.
The malware contains JavaScript and Python stubs intended to execute the malware from other infected repositories.
The malicious npm versions ... import launchStageZero from a new file, lib/sckit.js, and invoke it from the plugin's existing registration and recall logic.
It contains templates to install itself in npm packages, Python packages, and GitHub Actions workflows, and can function like a worm by self-proliferating through GitHub and direct npm and PyPI package publishing.
Otherwise, it attempts to spawn that binary with stage0 --config64 and an embedded base64 configuration. The package analysis ... decoded a configuration that sets inventory_roots to ["$HOME"].
The malware references environment variables related to package publishing credentials and contains a Go regular expression to search for Generic JWTs, AWS access key IDs, GitHub tokens, GitLab tokens, npm access tokens, PyPI API tokens, and other secrets.
The payload harvests credential files including .npmrc, .vault-token, id_ecdsa, credentials.db, access_tokens.json, and stored_tokens.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A statically linked, cross-platform Go credential-stealing implant delivered through compromised npm and PyPI packages. It harvests developer and CI credentials, tokens, keys, environment variables, and secret files, then exfiltrates them to skyleen[.]fr. It receives signed C2 tasks and contains templates enabling self-propagation through GitHub Actions workflows and npm/PyPI package publishing.
A stripped Go-based credential-harvesting payload bundled with compromised npm plugin releases. It inventories the user's home directory and can access inherited process-environment secrets and user prompt content. Recovered matching patterns target cloud, source-control, package-registry, AI-service, infrastructure, business-service, and general secret tokens. Its configuration specifies external endpoints that appear intended for control, preflight, and result handling, though successful exfiltration was not established.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.