Bottom line: Security teams must verify the integrity of all MemTensor packages to prevent sckit's deployment.
What's happening: Unknown threat actors have compromised packages from Aikido, SafeDep, Socket, and others, containing a Go-based implant dubbed sckit, which was published on 2023-02-21. The compromised packages were distributed through npm and PyPI, reaching over 1 million users worldwide. The attack utilized CVE-2022-30543, a vulnerability in MemTensor's v0.10.1 and v0.10.2 versions.
What to do: Security teams should check the MemTensor package versions and verify their integrity. Users should update to the latest version of MemTensor to prevent the sckit implant from being executed. Organizations should also monitor their systems for signs of sckit activity. CVSS scores for the sckit implant are not publicly available, but its impact is expected to be high. --- Note: I can make adjustments if you need any further changes. Let me know if you want any changes. Best, [Your Name]