security1 publisher
A pushed commit pulled MemTensor's npm and PyPI publish tokens out of its own release workflow
Three versions of MemTensor's MemOS Cloud plugin on npm and MemoryOS 2.0.34 on PyPI launch a Go stealer called sckit that reads the host environment and the user's prompt text, and the npm versions are still installable.
Publishers:thehackernews.com
Reality
- Evidence66
- Adoption28
- Hype gap+12
- Incentives60
- Confidence58