Evidence · DiggingBeagle record

Sckit supply-chain worm hits MemTensor npm and PyPI scopes

StepSecurity reproduction and artifact analysis showing the compromised OpenClaw plugin launches the bundled sckit payload during ordinary gateway and memory-recall paths, passes the host process environment, and passes the current user prompt during recall.

Published
Sep 23, 2026
Source role
independent technical reproduction

Evidence record

StepSecurity reproduction and artifact analysis showing the compromised OpenClaw plugin launches the bundled sckit payload during ordinary gateway and memory-recall paths, passes the host process environment, and passes the current user prompt during recall.

Read the original source ↗

Claim-level citations (3)

Cite this record

DiggingBeagle. “Sckit supply-chain worm hits MemTensor npm and PyPI scopes.” Published Sep 23, 2026. https://diggingbeagle.com/sources/sckit-supply-chain-worm-hits-memtensor-npm-and-pypi-scopes/

Citation guidance