Malicious code in memoryos (PyPI)
A malicious version 2.0.34 of the MemoryOS Python package on PyPI was published containing a Go-based implant named sckit. This implant runs a background binary that collects various credential files from the user's home directory and exfiltrates them to attacker-controlled servers under skyleen.fr. It also includes functionality to propagate itself into other repositories and packages accessible with the stolen credentials. The implant uses encrypted communication with its command-and-control servers and deletes itself after execution. Additionally, the package's build backend can steal CI environment publishing tokens, enabling further compromise of downstream package publishing.
AI Analysis
Technical Summary
On September 23, 2026, malicious versions of the MemoryOS Python package (version 2.0.34) were published containing a prebuilt Go implant called sckit. Upon import, the package launches a detached Go binary that collects credential files such as .npmrc, .pypirc, .git-credentials, SSH private keys, vault tokens, and various token caches from the user's home directory. The implant exfiltrates these credentials to multiple attacker-controlled domains under skyleen.fr using a secure protocol involving CBOR, X25519 key exchange, and XChaCha20-Poly1305 encryption. The implant also has code to copy itself into other repositories and packages accessible with stolen credentials. The package's build backend modifies CI environment variables to execute a signed payload that steals publishing tokens from GitHub Actions environments, enabling the attacker to compromise downstream package publishing. The implant deletes its binary after execution to evade detection. This is a supply-chain compromise with clear malicious intent targeting credential theft and propagation.
Potential Impact
The implant steals a wide range of sensitive credentials from the user's home directory, including package manager credentials, Git credentials, SSH private keys, vault tokens, and cached tokens. These stolen credentials are sent to attacker-controlled infrastructure, enabling further compromise of developer environments and potentially other repositories and packages. The CI environment token theft allows attackers to hijack downstream package publishing workflows, increasing the scope of the supply-chain compromise. The implant's self-deletion and encrypted communications make detection and analysis more difficult.
Mitigation Recommendations
No official patch or remediation is stated in the provided data. Users should immediately stop using version 2.0.34 of the MemoryOS package and remove it from their environments. Audit and revoke any potentially compromised credentials, including package manager tokens, SSH keys, and CI environment tokens. Review CI/CD pipelines for unauthorized environment variable modifications or payload executions. Monitor for suspicious network connections to the indicated attacker domains. Check the vendor advisory or PyPI for updates or fixed versions before resuming use.
Malicious code in memoryos (PyPI)
Description
A malicious version 2.0.34 of the MemoryOS Python package on PyPI was published containing a Go-based implant named sckit. This implant runs a background binary that collects various credential files from the user's home directory and exfiltrates them to attacker-controlled servers under skyleen.fr. It also includes functionality to propagate itself into other repositories and packages accessible with the stolen credentials. The implant uses encrypted communication with its command-and-control servers and deletes itself after execution. Additionally, the package's build backend can steal CI environment publishing tokens, enabling further compromise of downstream package publishing.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
On September 23, 2026, malicious versions of the MemoryOS Python package (version 2.0.34) were published containing a prebuilt Go implant called sckit. Upon import, the package launches a detached Go binary that collects credential files such as .npmrc, .pypirc, .git-credentials, SSH private keys, vault tokens, and various token caches from the user's home directory. The implant exfiltrates these credentials to multiple attacker-controlled domains under skyleen.fr using a secure protocol involving CBOR, X25519 key exchange, and XChaCha20-Poly1305 encryption. The implant also has code to copy itself into other repositories and packages accessible with stolen credentials. The package's build backend modifies CI environment variables to execute a signed payload that steals publishing tokens from GitHub Actions environments, enabling the attacker to compromise downstream package publishing. The implant deletes its binary after execution to evade detection. This is a supply-chain compromise with clear malicious intent targeting credential theft and propagation.
Potential Impact
The implant steals a wide range of sensitive credentials from the user's home directory, including package manager credentials, Git credentials, SSH private keys, vault tokens, and cached tokens. These stolen credentials are sent to attacker-controlled infrastructure, enabling further compromise of developer environments and potentially other repositories and packages. The CI environment token theft allows attackers to hijack downstream package publishing workflows, increasing the scope of the supply-chain compromise. The implant's self-deletion and encrypted communications make detection and analysis more difficult.
Mitigation Recommendations
No official patch or remediation is stated in the provided data. Users should immediately stop using version 2.0.34 of the MemoryOS package and remove it from their environments. Audit and revoke any potentially compromised credentials, including package manager tokens, SSH keys, and CI environment tokens. Review CI/CD pipelines for unauthorized environment variable modifications or payload executions. Monitor for suspicious network connections to the indicated attacker domains. Check the vendor advisory or PyPI for updates or fixed versions before resuming use.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-16475
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["PyPI"]
Threat ID: 6ab4be71f7a7c54106f0d460
Added to database: 09/24/2026, 06:08:49 UTC
Last enriched: 09/24/2026, 06:54:28 UTC
Last updated: 09/24/2026, 22:12:49 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.