npm과 PyPI의 MemTensor 패키지가 해킹되어 sckit 크리덴셜 도둑이 배포되었습니다.
알 수 없는 위협 행위자들이 npm과 Python Package Index (PyPI)에서 두 개의 합법적인 MemTensor 패키지를 해킹하여 윈도우, 리눅스, macOS에 대한 플랫폼 특정 Go 기반 임플란트인 sckit을 배포했습니다. Aikido, SafeDep, Socket, StepSecurity의 보고서에 따르면, 해당 라이브러리는 위험에 노출되어 있습니다. 사용자들은 이 패키지를 사용하는 것을 재검토해야 합니다.
Compromised MemTensor packages on npm and PyPI are delivering the sckit credential stealer.
Unknown threat actors have successfully compromised two legitimate MemTensor packages on npm and PyPI to deliver a platform-specific Go-based implant called sckit, targeting Windows, Linux, and macOS. Reports from Aikido, SafeDep, Socket, and StepSecurity indicate that these libraries are at risk. Users are advised to review their use of these packages.