Mobile Security & Privacy Malicious ‘sckit’ Worm Targets MemTensor Packages on npm and PyPI to Harvest Developer Credentials September 23, 2026 Lina Irawan Unknown threat actors have successfully compromised legitimate MemTensor packages across both the npm and Python Package Index (PyPI) software repositories in a sophisticated supply chain attack. The compromised libraries are…