Trust & Security
The First Supply-Chain Worm Targeting AI Agent Memory Infrastructure Just Hit npm and PyPI
A credential stealer called sckit hooked into MemTensor MemOS at the runtime level — bypassing install-time scanners, capturing agent prompts, and carrying self-propagation code that targets the publishing tokens developers trust most.
◆ Heath Callahan