Unknown threat actors compromised two legitimate MemTensor packages on the npm and Python Package Index (PyPI) repositories, according to a report from Aikido cited by The Hacker News. The tampered packages were used to deliver a platform-specific, Go-based implant called sckit, which is designed to run on Windows, Linux, and macOS.

The attack is notable because it abused trusted open-source packages rather than introducing new malicious ones, and the payload was tailored to the victim's operating system. Aikido's findings indicate the same campaign affected both npm and PyPI, with no reported difference in how the two packages were compromised.

The sckit implant functions as a credential stealer, though the report does not specify which credentials or data it targets. The Hacker News notes that the attackers remain unidentified, and no further details about the scope of the compromise or affected users have been disclosed.